Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Releases Advisory on Salesloft Drift Security Incident

SolarWinds Releases Advisory on Salesloft Drift Security Incident

Posted on September 19, 2025September 19, 2025 By CWS

SolarWinds has launched an advisory concerning a safety incident involving the Salesloft Drift integration for Salesforce, which led to unauthorized information entry.

The corporate confirmed that its personal techniques weren’t impacted by the breach, however is treating the matter with excessive precedence.

The safety incident originated from compromised OAuth tokens related to the Salesloft Drift software, a well-liked device used to combine gross sales and advertising features with Salesforce.

Attackers exploited these compromised tokens to achieve unauthorized entry to a number of Salesforce buyer environments. As soon as inside, they have been capable of export vital volumes of knowledge.

The first aim of the risk actors seems to have been the acquisition of delicate credentials, equivalent to entry keys and passwords, saved inside the compromised Salesforce situations.

One of these assault highlights the dangers of third-party integrations, the place a vulnerability in a single software can create a pathway right into a a lot bigger ecosystem, affecting quite a few organizations that depend on the identical software program stack.

SolarWinds Confirms No Influence

SolarWinds launched a direct inside investigation to evaluate its personal publicity to the vulnerability.

The corporate’s safety crew decided that whereas SolarWinds does use Salesforce as a part of its enterprise operations, it doesn’t make the most of the Salesloft Drift integration.

This key distinction meant that SolarWinds’ Salesforce occasion was not prone to the assault vector used on this breach. In a public assertion, the corporate confirmed that its techniques and information stay safe.

Regardless of not being straight affected, SolarWinds emphasised that it’s treating the incident as a high-priority concern and has proactively reviewed its inside safety protocols to make sure the integrity of its setting. The corporate can also be constantly monitoring the state of affairs for any evolving threats.

This occasion serves as a crucial reminder of the availability chain dangers inherent in fashionable cloud-based software program environments. Many organizations depend on an internet of interconnected third-party purposes to reinforce the performance of core platforms like Salesforce.

Nonetheless, every integration provides a brand new layer to the group’s assault floor. The compromise of OAuth tokens, particularly, is a potent risk, as these tokens can grant purposes intensive permissions to entry, modify, and exfiltrate information.

The incident underscores the necessity for organizations to conduct rigorous safety vetting of all third-party purposes and to audit the permissions granted to those integrations frequently.

Imposing the precept of least privilege and implementing sturdy monitoring for uncommon information entry patterns are important measures to mitigate such dangers.

Discover this Story Attention-grabbing! Observe us on Google Information, LinkedIn, and X to Get Extra Prompt Updates.

Cyber Security News Tags:Advisory, Drift, Incident, Releases, Salesloft, Security, SolarWinds

Post navigation

Previous Post: GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware
Next Post: CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428

Related Posts

Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access Cyber Security News
Hackers Allegedly Claim Leak of LG Source Code, SMTP, and Hardcoded Credentials Hackers Allegedly Claim Leak of LG Source Code, SMTP, and Hardcoded Credentials Cyber Security News
Critical Flaw in Kea DHCP Poses Remote Crash Risk Critical Flaw in Kea DHCP Poses Remote Crash Risk Cyber Security News
SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards Cyber Security News
How SOC Teams Detect Can Detect Cyber Threats Quickly Using Threat Intelligence Feeds How SOC Teams Detect Can Detect Cyber Threats Quickly Using Threat Intelligence Feeds Cyber Security News
Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI
  • Mac Users Face New Cloudflare-Themed Malware Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI
  • Mac Users Face New Cloudflare-Themed Malware Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark