시가총액: $2.2043T 0.58%
거래량(24시간): $56.8553B 3.76%
  • 시가총액: $2.2043T 0.58%
  • 거래량(24시간): $56.8553B 3.76%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2043T 0.58%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

Salesloft 위반 : CloudFlare의 응답 및 고객에 대한 파급 효과

2025/09/03 01:10

Saas 공급망 공격의 위협이 증가함에 따라 Salesloft 위반, CloudFlare의 반응 및 잠재적 인 고객 영향에 대한 깊은 다이빙.

Salesloft 위반 : CloudFlare의 응답 및 고객에 대한 파급 효과

Oh snap! A breach? Yeah, we're diving deep into the Salesloft breach, Cloudflare's response, and the customer impact. It's a wild ride, so buckle up!

오, 스냅! 위반? 예, 우리는 Salesloft 위반, CloudFlare의 응답 및 고객 영향에 깊이 빠져들고 있습니다. 거친 타는거야, 버클 업!

The Salesloft Breach: A Wake-Up Call

Salesloft 위반 : 모닝콜

Last week, Cloudflare got pinged about the Salesloft Drift breach. Turns out, some shady characters waltzed into Cloudflare's Salesforce instance, grabbing customer contact info and support case data. Sensitive stuff like access tokens might've been exposed. Cloudflare is urging customers to rotate any credentials shared in support channels. This incident highlights the growing risks of SaaS supply chain attacks, where compromising one service can lead to breaches in others. It's like a domino effect, but with data.

지난주 Cloudflare는 Salesloft 드리프트 위반에 대해 핑을했습니다. 일부 그늘진 캐릭터는 CloudFlare의 Salesforce 인스턴스로 왈츠로, 고객 연락처 정보를 잡고 사례 데이터를 지원합니다. 액세스 토큰과 같은 민감한 내용이 노출되었을 수 있습니다. CloudFlare는 고객에게 지원 채널에서 공유되는 자격 증명을 회전하도록 촉구합니다. 이 사건은 SaaS 공급망 공격의 위험이 증가 함을 강조하며, 하나의 서비스를 타협하면 다른 서비스가 위반 될 수 있습니다. 도미노 효과와 같지만 데이터가 있습니다.

Cloudflare's Swift Response

CloudFlare의 신속한 응답

When the alarm bells rang on August 23, 2025, Cloudflare's security team jumped into action. They cut off the bad guys' access, secured their third-party ecosystem, and analyzed the customer impact. It was a full-blown security incident response, involving everyone from legal to product teams. They even rotated 104 Cloudflare API tokens, just to be safe. No suspicious activity was found, but hey, better safe than sorry, right?

2025 년 8 월 23 일에 알람 벨이 울렸을 때 Cloudflare의 보안 팀이 행동에 뛰어 들었습니다. 그들은 Bad Guys의 접근을 차단하고 제 3 자 생태계를 확보했으며 고객 영향을 분석했습니다. 법률에서 제품 팀에 이르기까지 모든 사람을 포함하는 본격적인 보안 사고 대응이었습니다. 그들은 심지어 104 CloudFlare API 토큰을 회전 시켰습니다. 의심스러운 활동은 발견되지 않았지만 죄송합니다. 죄송합니다.

GRUB1: The Threat Actor in the Shadows

GRUB1 : 그림자의 위협 행위자

Cloudflare's threat intelligence squad, Cloudforce One, pinned the attack on an advanced threat actor dubbed GRUB1. These guys were sneaky, compromising Salesforce data between August 12-17, 2025. They didn't grab attachments, but the text in support cases was fair game. This included customer contact info, case subject lines, and the juicy details in the case correspondence. GRUB1's goal? Harvesting credentials and customer info for future attacks. Talk about a long game!

Cloudflare의 위협 인텔리전스 팀인 Cloudforce One은 Grub1이라는 고급 위협 행위자에 대한 공격을 고정했습니다. 이 사람들은 2025 년 8 월 12-17 일 사이에 영업 인력 데이터를 타협했으며 첨부 파일을 잡지 못했지만 지원 사례의 텍스트는 공정한 게임이었습니다. 여기에는 고객 연락처 정보, 사례 제목 줄 및 사례 서신의 수분이 많은 세부 사항이 포함되었습니다. Grub1의 목표? 향후 공격을위한 자격 증명 및 고객 정보 수확. 긴 게임에 대해 이야기하십시오!

Customer Impact: What's the Big Deal?

고객 영향 : 큰 문제는 무엇입니까?

Here's the skinny: if you shared any sensitive info with Cloudflare through support cases, consider it compromised. Rotate those credentials, stat! Cloudflare notified all affected customers and is urging everyone to disconnect Salesloft and review their support case data. It's a pain, but necessary.

Skinny는 다음과 같습니다. 지원 사례를 통해 CloudFlare와 민감한 정보를 공유 한 경우 손상된 것을 고려하십시오. 해당 자격 증명을 회전하십시오. CloudFlare는 영향을받는 모든 고객에게 알리고 모든 사람이 Salesloft를 연결 해제하고 지원 사례 데이터를 검토 할 것을 촉구합니다. 고통이지만 필요합니다.

The Bigger Picture: SaaS Security Blind Spots

더 큰 그림 : SaaS 보안 사각 지대

This breach isn't just a one-off. It's part of a larger trend where attackers are targeting OAuth tokens to bypass traditional security measures. These tokens, used for app integrations, can grant unauthorized access to sensitive data if not properly monitored. It's not just about shadow SaaS anymore; it's about shadow integrations – the web of app relationships that no one's watching. One misconfigured integration, one breached app, and bam, your Salesforce data is up for grabs.

이 위반은 일회성이 아닙니다. 공격자가 전통적인 보안 조치를 우회하기 위해 Oauth 토큰을 목표로하는 더 큰 트렌드의 일부입니다. 앱 통합에 사용되는 이러한 토큰은 제대로 모니터링되지 않으면 민감한 데이터에 대한 무단 액세스 권한을 부여 할 수 있습니다. 더 이상 Shadow Saa에 관한 것이 아닙니다. 그것은 아무도보고 있지 않은 앱 관계의 웹 인 Shadow Integrations에 관한 것입니다. 하나의 잘못된 구성 통합, 하나의 위반 된 앱 및 BAM, Salesforce 데이터는 GRABS에 적용됩니다.

Lessons Learned and Recommendations

학습과 권장 사항

So, what can you do to avoid becoming the next victim? Cloudflare recommends:

그렇다면 다음 피해자가되는 것을 피하기 위해 무엇을 할 수 있습니까? CloudFlare 권장 사항 :

  • Disconnect Salesloft and its applications.
  • Rotate credentials for all third-party apps connected to Salesforce.
  • Implement frequent credential rotation.
  • Review support case data for exposed sensitive info.
  • Conduct forensics and enhance monitoring.
  • Enforce least privilege for third-party apps.

Basically, tighten up your SaaS security game. It's not enough to secure user accounts; you need to monitor app-to-app trust chains and OAuth permissions. Otherwise, you're leaving the door open for attackers to waltz right in.

기본적으로 SaaS 보안 게임을 강화하십시오. 사용자 계정을 확보하는 것만으로는 충분하지 않습니다. App-to-App Trust 체인 및 OAuth 권한을 모니터링해야합니다. 그렇지 않으면, 당신은 공격자들이 왈츠를 바로 들어 올릴 수 있도록 문을 열어두고 있습니다.

Cloudflare's Apology and Commitment

Cloudflare의 사과와 헌신

Cloudflare took responsibility for the breach, apologizing for letting their customers down. They're committed to developing new capabilities to defend against such attacks and sharing threat intelligence with the broader security community. They're also urging everyone to approach new tools with careful scrutiny and monitor what they can access. It's a learning experience for everyone involved.

CloudFlare는 고객을 실망시키는 것에 대해 사과하면서 위반에 책임을졌습니다. 그들은 그러한 공격을 방어하고 더 넓은 보안 커뮤니티와 위협 정보를 공유 할 수있는 새로운 기능을 개발하기 위해 노력하고 있습니다. 또한 모든 사람들이 신중한 조사를 통해 새로운 도구에 접근하고 액세스 할 수있는 내용을 모니터링 할 것을 촉구합니다. 관련된 모든 사람을위한 학습 경험입니다.

In Conclusion: Stay Vigilant, My Friends

결론적으로 : 내 친구들, 경계를 유지하십시오

The Salesloft breach is a stark reminder of the interconnected risks in today's technology landscape. SaaS security is no longer just about securing individual apps; it's about securing the entire ecosystem of integrations and trust relationships. So, stay vigilant, monitor your OAuth tokens, and don't let those shadow integrations bite you in the you know what. Keep calm and carry on, and remember, in the world of SaaS security, paranoia is your friend.

Salesloft 위반은 오늘날의 기술 환경에서 상호 연결된 위험을 상기시켜줍니다. SaaS Security는 더 이상 개별 앱 보안에 관한 것이 아닙니다. 통합 및 신뢰 관계의 전체 생태계를 확보하는 것입니다. 따라서 경계를 유지하고, Oauth 토큰을 모니터링하고, 그 그림자 통합이 당신을 알고있는 것에 물리도록하지 마십시오. Saas Security의 세계에서 편집증은 친구입니다.

원본 소스:cloudflare

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年08月07日 에 게재된 다른 기사