Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Posted on September 8, 2025September 8, 2025 By CWS

Qualys has confirmed it was impacted by a widespread provide chain assault that focused the Salesloft Drift advertising and marketing platform, leading to unauthorized entry to a portion of its Salesforce information.

The breach originated from a classy cyberattack marketing campaign focusing on Salesloft Drift, a third-party Software program-as-a-Service (SaaS) software utilized by Qualys to automate gross sales workflows and handle advertising and marketing leads.

Based on the corporate, the attackers efficiently stole OAuth authentication tokens that linked the Drift software to Qualys’s Salesforce occasion. The malicious actors then used these tokens to realize unauthorized entry.

Qualys specified that the entry was restricted to some data inside its Salesforce surroundings, which is primarily used for managing leads and call data.

The corporate confirmed in its assertion that the assault didn’t compromise its foundational safety infrastructure. There was no influence on the Qualys manufacturing environments, together with its shared and personal platforms, codebase, or any buyer information hosted on the Qualys Cloud Platform. Moreover, all Qualys platforms, brokers, and scanners remained totally useful with no operational disruptions.

Upon changing into conscious of the incident, Qualys instantly activated its incident response plan. The corporate’s safety crew took swift motion to comprise the risk by disabling all Drift integrations with its Salesforce information, successfully reducing off the attackers’ entry.

To assist its inner investigation efforts, Qualys has engaged the distinguished cybersecurity agency Mandiant. Mandiant is reportedly aiding most of the different organizations that have been additionally impacted by this widespread marketing campaign towards Salesloft Drift.

Confirmed victims of this provide chain assault embody:

Palo Alto Networks: The cybersecurity agency confirmed the publicity of enterprise contact data and inner gross sales information from its CRM platform.

Zscaler: The cloud safety firm reported that buyer data, together with names, contact particulars, and a few assist case content material, was accessed.

Google: Along with being an investigator, Google confirmed a “very small quantity” of its Workspace accounts have been accessed by the compromised tokens.

Cloudflare: Cloudflare has confirmed a knowledge breach the place a classy risk actor accessed and stole buyer information from the corporate’s Salesforce occasion.

PagerDuty has confirmed a safety incident that resulted in unauthorized entry to a few of its information saved in Salesforce.

Tenable has confirmed a knowledge breach that uncovered the contact particulars and assist case data of a few of its clients.

Discover this Story Fascinating! Observe us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:Accessed, Attack, Breach, Chain, Confirms, Data, Hackers, Qualys, Salesforce, Supply

Post navigation

Previous Post: Salesloft GitHub Account Compromised Months Before Salesforce Attack
Next Post: Hackers Weaponizee Amazon Simple Email Service to Send 50,000+ Malicious Emails Per Day

Related Posts

CredShields Enhances OWASP 2026 Smart Contract Security CredShields Enhances OWASP 2026 Smart Contract Security Cyber Security News
29.7 Tbps DDoS Attack Via Aisuru botnet Breaks Internet With New World Record 29.7 Tbps DDoS Attack Via Aisuru botnet Breaks Internet With New World Record Cyber Security News
M Cryptocurrency Theft Linked to LastPass Password Manager DataBreach $35M Cryptocurrency Theft Linked to LastPass Password Manager DataBreach Cyber Security News
CRESCENTHARVEST Malware Targets Iran Protesters CRESCENTHARVEST Malware Targets Iran Protesters Cyber Security News
Salt Typhoon Using Zero-Day Exploits and DLL Sideloading Techniques to Attack Organizations Salt Typhoon Using Zero-Day Exploits and DLL Sideloading Techniques to Attack Organizations Cyber Security News
1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon 1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark