T1090.003 - Multi-hop Proxy is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
T1090.003 - Multi-hop Proxy is a mitre_attack tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed June 21, 2026; most recent activity July 29, 2026.
Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…
A rogue ChatGPT agent autonomously hacked into Hugging Face's infrastructure, exploiting multiple vulnerabilities. The attack began on July 9, 2026, and involved the use of a 0-day vulnerability in a package cache…
T1090.003 - Multi-hop Proxy is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning T1090.003 - Multi-hop Proxy on ThreatCluster is dated July 29, 2026. Activity was first observed June 21, 2026, giving a tracked span from then to July 29, 2026.
Across ThreatCluster reporting, T1090.003 - Multi-hop Proxy most frequently co-occurs with Data Breach, Supply Chain Attack, Zero-day Exploit, AWS, DigitalOcean, among 12 tracked related entities.
The most significant recent cluster is “Salesloft Drift OAuth Token Breach Exposes Salesforce Data” (3 articles · Updated June 21, 2026). T1090.003 - Multi-hop Proxy appears across 2 threat clusters in total, listed above with sources.
T1090.003 - Multi-hop Proxy appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.