Saturday, September 13, 2025
avgc-xr
No Result
View All Result
  • Home
  • News
  • About
  • Events
  • Spotlight
  • Launches
  • Digital
  • Contact us
  • Home
  • News
  • About
  • Events
  • Spotlight
  • Launches
  • Digital
  • Contact us
No Result
View All Result
avgc-xr
No Result
View All Result
Home All

Zscaler Suffers Salesforce Data Breach via Salesloft Drift OAuth Token Compromise

by Sai Kiran
September 10, 2025
in All
0
Zscaler Suffers Salesforce Data Breach via Salesloft Drift OAuth Token Compromise
0
SHARES
0
VIEWS
FacebookTwitterWhatsappLinkedin

Zscaler, a leading cloud security provider, confirmed a data breach stemming from a compromised Salesloft Drift integration with Salesforce. Attackers exploited stolen OAuth tokens to access customer contact records and limited support-case text data. Crucially, Zscaler’s internal systems and core infrastructure were unaffected. ([turn0news20]; [turn0search9])

The breach is part of a larger supply-chain attack targeting OAuth tokens tied to Salesloft Drift, a popular AI-driven chat and sales workflow tool—impacting over 700 organizations globally, as tracked by threat actor UNC6395 and security firms Google’s Threat Intelligence Group and Mandiant. ([turn0search9]; [turn0search8])

Exposed data includes:

  • Names, business emails, job titles, phone numbers, and regional info
  • Commercial/licenses tied to Zscaler products
  • Plain-text fields from select support cases—excluding attachments and files
    ([turn0news20]; [turn0search2])

Zscaler acted swiftly, revoking Drift access, rotating API/OAuth tokens, launching a forensic investigation with Salesforce, and ramping up third-party risk governance and phishing safeguards. As of now, there is no evidence of data misuse. ([turn0news20]; [turn0search2]; [turn0news21])


Why It Matters for AVGC & Tech Ecosystems

InsightImplication
Trust in Vendor EcosystemsEven industry-leading security firms can be compromised via SaaS integration pathways.
Critical Role of Token ManagementOAuth tokens can bypass MFA, highlighting the importance of secure token governance.
Shared Risk in SaaS Supply ChainsA breach at a third-party SaaS tool can ripple through dependent organizations, regardless of their own defenses.
Urgency of Defense-in-DepthRobust incident response, zero-trust design, and tight SaaS integration policies are vital for business resilience.
Tags: Salesforce OAuth token attackSalesloft Drift breachUNC6395 supply chain breachZscaler data breach
Sai Kiran

Sai Kiran

Next Post
The Whitest Kids U Know: MARS Adult Animated Comedy Heads to Deluxe Blu-Ray in Early 2026

The Whitest Kids U Know: MARS Adult Animated Comedy Heads to Deluxe Blu-Ray in Early 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

“Meta Tiramisu and Boba 3 prototype VR headsets on display at SIGGRAPH 2025 with high-clarity screens and wide field of view demonstration.”

Meta Unveils Tiramisu & Boba 3 Prototypes Aiming for Visual Turing Test at SIGGRAPH 2025

14 hours ago
“Book authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson at a hearing related to Anthropic’s class action over AI-trained pirated books”

Anthropic Agrees to $1.5 Billion Settlement After Authors Sue Over Pirated Books Used to Train Claude

14 hours ago
“Developer reviewing AI-generated code on screen with highlighted potential security and style issues”

Vibe Coding Surges—but Governance Risks Could Undermine the Productivity Boom

15 hours ago

Popular News

  • “Meta Tiramisu and Boba 3 prototype VR headsets on display at SIGGRAPH 2025 with high-clarity screens and wide field of view demonstration.”

    Meta Unveils Tiramisu & Boba 3 Prototypes Aiming for Visual Turing Test at SIGGRAPH 2025

    0 shares
    Share 0 Tweet 0
  • Anthropic Agrees to $1.5 Billion Settlement After Authors Sue Over Pirated Books Used to Train Claude

    0 shares
    Share 0 Tweet 0
  • Vibe Coding Surges—but Governance Risks Could Undermine the Productivity Boom

    0 shares
    Share 0 Tweet 0
  • NODWIN Gaming Acquires Sony’s Stake, Becomes Majority Shareholder of Evo

    0 shares
    Share 0 Tweet 0
  • *“The Wizard of Oz at Sphere” Pulls in Up to $2 Million per Day in Las Vegas Immersive Run

    0 shares
    Share 0 Tweet 0
  • hyderabad
  • @avgc-xr.com

NEWS

VFX
Trending
Television
Technology
Streaming
people
Organisations
National
Movies
Gaming

TRENDING

Meta Unveils Tiramisu & Boba 3 Prototypes Aiming for Visual Turing Test at SIGGRAPH 2025

Anthropic Agrees to $1.5 Billion Settlement After Authors Sue Over Pirated Books Used to Train Claude

Vibe Coding Surges—but Governance Risks Could Undermine the Productivity Boom

NODWIN Gaming Acquires Sony’s Stake, Becomes Majority Shareholder of Evo

*“The Wizard of Oz at Sphere” Pulls in Up to $2 Million per Day in Las Vegas Immersive Run

MOST POPULAR

Meta Unveils Tiramisu & Boba 3 Prototypes Aiming for Visual Turing Test at SIGGRAPH 2025

Anthropic Agrees to $1.5 Billion Settlement After Authors Sue Over Pirated Books Used to Train Claude

Vibe Coding Surges—but Governance Risks Could Undermine the Productivity Boom

NODWIN Gaming Acquires Sony’s Stake, Becomes Majority Shareholder of Evo

*“The Wizard of Oz at Sphere” Pulls in Up to $2 Million per Day in Las Vegas Immersive Run

No Result
View All Result
  • Home
  • News
  • About
  • Events
  • Digital
  • Contact us
  • Spotlight
  • Launches
  • Feedzy Demo Page