Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Tenable Confirms Data Breach – Hackers Accessed Customers Contact Details

Tenable Confirms Data Breach – Hackers Accessed Customers Contact Details

Posted on September 8, 2025September 8, 2025 By CWS

Tenable has confirmed a knowledge breach that uncovered the contact particulars and help case data of a few of its clients.

The corporate acknowledged the incident is a part of a broader information theft marketing campaign focusing on an integration between Salesforce and the Salesloft Drift advertising and marketing software, which has affected quite a few organizations.

In a public assertion, Tenable expressed its dedication to transparency and detailed the extent of the breach. The corporate’s investigation discovered that an unauthorized person had gained entry to a phase of buyer data saved inside its Salesforce occasion.

Whereas Tenable’s core merchandise and the info inside them stay safe, the incident has raised considerations concerning the safety of third-party software integrations inside main enterprise platforms.

Uncovered Knowledge

The knowledge accessed by the unauthorized celebration was restricted to information inside Tenable’s Salesforce surroundings. This included:

Generally out there enterprise contact data, akin to buyer names, enterprise electronic mail addresses, and cellphone numbers.

Regional and placement references related to buyer accounts.

Topic strains and preliminary descriptions that clients supplied when opening a help case.

Tenable has famous that presently, there isn’t any proof to counsel that the attackers have actively misused any of this data.

The breach at Tenable was not an remoted assault however is linked to a wider, refined marketing campaign that safety consultants have been monitoring. This marketing campaign particularly exploits a vulnerability within the integration between Salesforce and Salesloft Drift, a preferred gross sales engagement platform.

Attackers have been utilizing this vector to exfiltrate information from the Salesforce situations of varied firms that use the built-in functions. Tenable confirmed it was one among many organizations impacted by this coordinated effort.

Tenable’s Response and Mitigation

Upon discovering the incident, Tenable took speedy motion to safe its programs and defend buyer information. The corporate has outlined a number of steps it has taken to deal with the problem:

All doubtlessly compromised credentials for Salesforce, Drift, and associated integrations had been promptly revoked and rotated.

The Salesloft Drift software, together with all functions that built-in with it, was disabled and faraway from Tenable’s Salesforce occasion.

The corporate has additional hardened its Salesforce surroundings and different related programs to forestall future exploitation.

Tenable utilized identified Indicators of Compromise (IoCs) shared by Salesforce and cybersecurity consultants to establish and block malicious exercise.

Steady monitoring of its Salesforce and different SaaS options is ongoing to detect any exposures or uncommon exercise.

Tenable is advising its clients to stay vigilant and has really helpful that they comply with the proactive steps outlined by Salesforce and main safety consultants to safe their very own programs.

Confirmed victims of this provide chain assault embrace:

Palo Alto Networks: The cybersecurity agency confirmed the publicity of enterprise contact data and inner gross sales information from its CRM platform.

Zscaler: The cloud safety firm reported that buyer data, together with names, contact particulars, and a few help case content material, was accessed.

Google: Along with being an investigator, Google confirmed a “very small quantity” of its Workspace accounts had been accessed by the compromised tokens.

Cloudflare: Cloudflare has confirmed a knowledge breach the place a classy menace actor accessed and stole buyer information from the corporate’s Salesforce occasion.

PagerDuty has confirmed a safety incident that resulted in unauthorized entry to a few of its information saved in Salesforce.

Discover this Story Attention-grabbing! Comply with us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:Accessed, Breach, Confirms, Contact, Customers, Data, Details, Hackers, Tenable

Post navigation

Previous Post: How to Use End-to-End Encrypted Email
Next Post: Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data

Related Posts

RMM Tools: Vital for IT but Increasingly Misused by Hackers RMM Tools: Vital for IT but Increasingly Misused by Hackers Cyber Security News
OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically Cyber Security News
Four Hackers Arrested by UK Police for Attacks on M&S, Co-op and Harrods Stores Four Hackers Arrested by UK Police for Attacks on M&S, Co-op and Harrods Stores Cyber Security News
HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface Cyber Security News
Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware Cyber Security News
Obscure MCP API in Comet Browser Breaches User Trust, Enabling Full Device Control via AI Browsers Obscure MCP API in Comet Browser Breaches User Trust, Enabling Full Device Control via AI Browsers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark