T1213.003 - Code Repositories - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 21, 2026
Last Seen
June 24, 2026

Related Threat Clusters

  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026
  • AppleScript-Driven macOS Intrusions Exploiting User Deception

    Darktrace's Threat Research team identified a pattern of macOS intrusions leveraging ClickFix-style user deception. Attackers initiated the compromise through user-assisted execution of malicious updates, transitioning…

    2 articles · Updated June 24, 2026

Recent Intelligence Reports

  • From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
  • From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
  • Salesloft Drift OAuth Token Breach Enables Salesforce Data Theft in UNC6395 'Icarus ... — Rescana · June 21, 2026

CVSS v3.1 Breakdown