Zscaler, Palo Alto Networks Breached via Salesloft Drift
ID: 768cb625-da4f-5cf7-9672-55cb6d02cdac
STIX ID: report--768cb625-da4f-5cf7-9672-55cb6d02cdac
Feed Name: Dark Reading
Threat Score
A widespread supply-chain incident involving Salesloft's Drift integration (attributed to threat actor UNC6395) led to theft of OAuth/refresh tokens and mass exfiltration of Salesforce data from Aug. 8–18; numerous customers were impacted, including Zscaler and Palo Alto Networks, prompting revocation of tokens, vendor investigations (Mandiant/Unit 42), and guidance to audit and rotate exposed credentials and monitor for follow-on social engineering or credential abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
