原标题: Hackers Use Stolen Salesloft Drift Tokens to Raid Salesforce Instances
第一项始终是图钉的来源。总体可信度是各份资料对上方所用开始和结束时间支持程度的加权平均;资料每比最新的一份旧 180 天,权重减半。
GTIG:“最早从 2025 年 8 月 8 日起至少持续到 2025 年 8 月 18 日,攻击者通过与 Salesloft[2] Drift 第三方应用相关的被盗 OAuth 令牌攻击 Salesforce 客户实例。”
Salesloft's summary of Mandiant's investigation: engaged 26 August 2025, intrusion timeline 22 March to 5 September 2025 including GitHub reconnaissance with Salesloft access tokens, remediation concluded 30 September; Drift came back online on 16 September.
ShinyHunters told BleepingComputer the Drift thefts hit about 760 companies and 1.5 billion Salesforce records; victims confirmed include Google[1], Cloudflare[5], Zscaler, Palo Alto Networks, Tenable and CyberArk.
The FBI confirms UNC6395 used compromised Drift OAuth tokens in August 2025 and that on August 20 Salesloft[2], with Salesforce, revoked all Drift access and refresh tokens.
Cloudflare, notified on 23 August, says the attacker exfiltrated the text of its Salesforce support cases and that it found and rotated 104 Cloudflare API tokens in the stolen data.
有遗漏或错误吗?用你自己的话说明:能佐证此图钉的链接、不同的开始或结束日期及理由,或缺失、有误的信息。AI 会对照此图钉的来源进行核实,搜索更好的来源,并添加任何支持你说法的页面。图钉自身的来源仍然最重要。