ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Salesforce data missing? It might be due to Salesloft breach, Google says

Threat Score:
51
The Register Security
2 days ago
Part of cluster #2214
Salesforce data missing? It might be due to Salesloft breach, Google says

Overview

Cyber-crime Salesforce data missing? It might be due to Salesloft breach, Google says Attackers steal OAuth tokens to access third-party sales platform, then CRM data in 'widespread campaign' Google says a recent spate of Salesforce-related breaches was caused by attackers stealing OAuth tokens from the third-party Salesloft Drift app. Drift is used for automating sales processes, and it integrates with Salesforce databases, pulling relevant information such as leads and details into the platfor...

Continue Reading on Original Site

Related Articles

5 articles
1
Deception in depth: Defending against sophisticated and evolving PRC-nexus espionage campaigns

Deception in depth: Defending against sophisticated and evolving PRC-nexus espionage campaigns

Brighttalk • 8 hours ago

Presented by Patrick Whitsell, Security Engineer, Google Threat Intelligence Group and Austin Larsen, Principal Threat Analyst, Google Threat Intelligence Group

Score
83
Read more
2

WhatsApp Zero-Day Vulnerability Exploited with 0-Click Attacks to Hack Apple Devices

GB Hackers • 4 hours ago

WhatsApp Zero-Day Vulnerability Exploited with 0-Click Attacks to Hack Apple Devices WhatsApp has issued a critical security advisory addressing a newly discovered zero-day vulnerability, tracked as CVE-2025-55177, which has been exploited in highly sophisticated zero-click attacks targeting Mac and iOS users. The vulnerability, combined with an OS-level flaw (CVE-2025-43300), has raised alarms the potential compromise of user devices and data, including sensitive messages. Vulnerability Details

Score
81
Read more
3

TransUnion Data Breach Impacts 4.4 Million

SecurityWeek • 11 hours ago

The credit reporting firm did not name the third-party application involved in the incident, only noting that it was used for its US consumer support operations.

Score
81
Read more
4

WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

Cybersecurity News • 6 hours ago

A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems to compromise devices and access user data. WhatsApp has since patched the vulnerability and has […]

Score
79
Read more
5

Google Confirms Workspace Accounts Also Hit in Salesforce–Salesloft Drift Data Theft Campaign

SecurityWeek • 11 hours ago

Google says the same OAuth token compromise that enabled Salesforce data theft also let hackers access a small number of Workspace accounts via the Salesloft Drift integration.

Score
79
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

FILE PATH
/O Google Nest G Suite Kubernetes NCSC Pixel Privacy Sandbox Tavis Ormandy Broader topics Alphabet Engine Security More More Authentication Cybercrime Google More Authentication Cybercrime Google SalesForce Narrower topics 2FA Android App stores Biometrics Chrome Chromium Gemini Google AI Google Cloud Platform Google I/O Google Nest G Suite Kubernetes NCSC Pixel Privacy Sandbox Tavis Ormandy Broader topics Alphabet Engine Security TIP US OFF Send us news
ATTACK TYPES
Data Exfiltration
Data Theft
OAuth Token Abuse
OAuth Token Exploitation
OAuth Token Theft
INDUSTRIES
Cloud Services
Insurance
SaaS
Sales Automation
Technology
COMPANIES
Google
Salesforce
Salesloft
AGENCIES
NCSC
PLATFORMS
AWS
Android
Drift
GCP
Google Cloud Platform
APT GROUPS
Earth Lusca
UNC6395
RANSOMWARE
AnDROid
One
MALWARE
Gozi
MITRE ATT&CK
T1003
T1005
T1041
T1046
T1053
SECURITY VENDORS
Google Threat Intelligence Group
ARTICLE INFORMATION
Article #14973
Published 2 days ago
The Register Security

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration