❮ Back to blog
Third Party Integration Security

Zero trust stopped at the network with frontier AI

Network security and ZTNA can't stop AI-driven SaaS attacks. Learn why zero trust fails at the application layer and how Obsidian secures your Saa

4 min read

Network security has had a good decade. The perimeter firewall became a next-gen firewall, then a cloud-delivered SSE stack: secure web gateway, CASB, ZTNA, DLP, all in one policy engine, following the user wherever they work. Encrypted traffic gets inspected. Segmentation stops lateral movement that used to take down whole environments. ZTNA killed the flat VPN and made "never trust, always verify" something you could buy. If an attacker has to move a packet through your network to reach something, you're in decent shape. 

However, that’s where zero trust stops. Here's what the network sees when an attacker uses a stolen session token to log into Salesforce: an HTTPS connection to salesforce.com. That's it. The destination is sanctioned. The certificate is valid. The traffic pattern looks like every other sales rep on a Tuesday. There's no C2 beacon, no exfil to a suspicious domain, no lateral movement across a segment, because the attacker isn't on your network. They're on Salesforce's.

And an increasing share of the traffic never touches your network at all. When an employee connects an AI note-taker to Google Drive, the data flows from Google's servers to the vendor's servers. When a marketplace agent reads Workday, it does so from the vendor's cloud. When your own AI agent chains Slack to Salesforce to Snowflake, every hop is server-to-server. Your SSE proxy is watching the user's laptop. Nothing interesting is happening on the user's laptop.

Frontier AI made this the primary path

For years, going after the third party application estate required expertise that didn't scale: understanding each application's permission model well enough to know what a credential actually unlocked. So attackers took the paths that scaled, and those went through the network. Defenders spent accordingly.

Frontier models supply that expertise at machine cost. One operator can point agents at your identities, OAuth grants, and integrations in parallel, read every permission structure like a specialist, and find the low-severity findings that connect into a working path. The long tail of your SaaS estate, dormant tokens, local admins outside the IdP, grants from 2021, unowned agent identities, is now the cheapest thing to attack and the easiest to chain. None of it is reachable by a firewall rule.

Meanwhile the estate grows. Every OAuth consent screen is a standing grant that doesn't expire when interest fades and doesn't route through your proxy. Adoption is integration. Scope granted is blast radius inherited. The Context.ai compromise showed a small vendor's breach flowing straight into connected tenants without a single packet crossing a customer network. 

What this looks like during an attack

A dormant personal access token surfaces in a public repository. It belongs to a service account with broad Snowflake scope and no IP allowlist. The attacker queries from a cloud VM: TLS to snowflake.com, valid credentials, normal query volume spread over a week. From there, a readable knowledge base points to a local Salesforce admin outside the IdP. That admin authorizes a new "analytics" integration with org-wide read. Data leaves via the integration's own infrastructure.

Your SWG logged nothing, because no managed user did anything. Your CASB saw sanctioned apps behaving normally. Your ZTNA was never in the path. Every hop was authenticated, encrypted, and destined for a domain on your allow list.

Why CASBs aren’t enough 

It covers the traffic between your users and SaaS, and it does that well: shadow IT discovery, inline DLP, blocking uploads to unsanctioned tools. What it can't see is inside the application: sharing settings, permission drift, which of 400 OAuth apps is over-scoped, which service account hasn't been authenticated in a year but still has admin. It can't see 3rd party integrations or agents. API-mode CASB helps at the edges, but it was designed to classify data in a handful of apps, not to model entitlement relationships across hundreds.

"Zero trust" was supposed to mean continuous verification of every identity for every access. In practice the network stack verifies at the connection, then trusts the session. The application layer is where trust actually gets exercised, and it's where nobody is verifying.

Cover the gap with Obsidian 

Discovery: Obsidian connects to your SaaS and AI estate by API and builds a live, relationship-aware map of every identity, entitlement, integration, agent, and data path, normalized across applications that share no schema. It separates what's actually used from what was merely granted, and it traces multi-hop chains instead of listing findings. Shadow AI and unsanctioned integrations surface alongside the sanctioned ones. Network telemetry can't build this, because the relationships that make up an attack path never appear in traffic.

Governance: Obsidian drives the estate toward least privilege continuously: it identifies dormant tokens, over-scoped grants, local admins outside the IdP, and the users who can authorize new integrations, and it shows you the attack paths a frontier-capable adversary would chain them into. You remove the link, and the path is dead. Third-party integrations are scored by vendor, scope, and usage so stale or risky access gets retired before someone else finds it. The output is a blast radius that shrinks quarter over quarter.

Enforcement:  Obsidian's streaming detections watch identity behavior across every connected application, baselined per identity, so a service account querying Snowflake from a new cloud VM or an admin authorizing an org-wide integration is caught at the moment the adversary is learning what it can reach. High-confidence detections trigger containment inside the application: revoke the grant, terminate the session, strip the scope. Narrowly and automatically. A firewall block doesn't help when the traffic is to a destination you approved from a network you don't control. Revoking the identity does.

‍

To learn more about how frontier AI is shaping third party integrations and attackers economics

Read our blog

Frequently Asked Questions (FAQs)