|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Salesloft 드리프트 위반, 타임 라인 및 사이버 보안 회사에 대한 광범위한 영향에 대한 자세한 내용. 이 중요한 공급망 공격에 대한 정보를 유지하십시오.

The Salesloft Drift breach sent shockwaves through the cybersecurity world. With over 700 organizations affected, understanding the timeline and impact is crucial. Here's a breakdown of what happened.
Salesloft 드리프트 위반은 사이버 보안 세계를 통해 충격파를 보냈습니다. 700 개가 넘는 조직이 영향을 받으면 타임 라인과 영향을 이해하는 것이 중요합니다. 다음은 일어난 일에 대한 고장입니다.
The Breach: A Timeline of Events
위반 : 이벤트 타임 라인
The Salesloft Drift breach is a complex story unfolding over several months. Here's a simplified timeline:
Salesloft 드리프트 위반은 몇 달에 걸쳐 복잡한 이야기입니다. 간단한 타임 라인은 다음과 같습니다.
- March 2025: Threat actors compromise Salesloft's GitHub account.
- March - June 2025: Attackers download repository data and conduct reconnaissance on Salesloft and Drift environments.
- August 8-18, 2025: Using stolen OAuth tokens, attackers access and exfiltrate data from customer Salesforce instances.
- August 20, 2025: Salesloft and Salesforce revoke connections between Drift and Salesforce.
- August 26, 2025: Companies announce unauthorized access. Google warns of credential theft.
- August 28, 2025: Salesloft begins investigation with Mandiant.
- September 2-8, 2025: Cybersecurity firms including Palo Alto Networks, Zscaler, Cloudflare, Proofpoint, Tenable, Qualys, Rubrik, Spycloud, BeyondTrust, CyberArk, Elastic, Dynatrace, Cato Networks and BugCrowd disclose they were victims.
- September 6, 2025: Salesloft confirms GitHub compromise as the initial attack vector.
- September 8, 2025: Salesforce restores integration with Salesloft (excluding Drift).
Key Insights and Takeaways
주요 통찰력과 테이크 아웃
The Salesloft Drift breach underscores several critical points:
Salesloft 드리프트 위반은 몇 가지 중요한 점을 강조합니다.
- Supply Chain Risks: Third-party integrations, especially in SaaS environments, introduce significant risks.
- OAuth Token Security: Stolen OAuth tokens are a powerful attack vector, granting access without triggering typical alerts.
- Importance of Incident Response: Swift action, including isolating infrastructure and rotating credentials, is crucial in containing breaches.
- GitHub as a Target: This incident highlights the growing trend of attackers targeting code repositories like GitHub.
The Impact on Cybersecurity Companies
사이버 보안 회사에 미치는 영향
A particularly alarming aspect of this breach is the number of cybersecurity companies affected, including Cloudflare, Zscaler, Palo Alto Networks and many others. This suggests a deliberate targeting of organizations with access to sensitive data and security infrastructure. While these companies took quick action to mitigate impact on products and services, the potential reputational damage and cost of remediation are substantial.
이 위반의 특히 놀라운 측면은 Cloudflare, Zscaler, Palo Alto Networks 등을 포함하여 영향을받는 사이버 보안 회사의 수입니다. 이는 민감한 데이터 및 보안 인프라에 액세스 할 수있는 조직의 고의적 인 목표를 시사합니다. 이 회사들은 제품과 서비스에 대한 영향을 완화하기 위해 빠른 조치를 취했지만 잠재적 인 평판 손상과 치료 비용은 상당합니다.
My Two Cents: A Wake-Up Call
내 두 센트 : 모닝콜
The Salesloft Drift breach serves as a potent reminder of the interconnectedness of the modern SaaS ecosystem. It's no longer enough to focus solely on your own security posture; you must also rigorously assess the security practices of your vendors. Assume compromise and ensure proper segmentation and monitoring are in place. Ignoring the reality of supply chain risk is a recipe for disaster.
Salesloft 드리프트 위반은 현대 SaaS 생태계의 상호 연결성을 강력하게 상기시켜줍니다. 더 이상 자신의 보안 자세에만 집중하기에 충분하지 않습니다. 또한 공급 업체의 보안 관행을 엄격하게 평가해야합니다. 타협을 가정하고 적절한 세분화 및 모니터링이 마련되어 있는지 확인하십시오. 공급망 위험의 현실을 무시하는 것은 재난의 레시피입니다.
Salesforce Restores Salesloft Integration
Salesforce는 Salesloft 통합을 복원합니다
After investigation, Salesforce has restored integration with the Salesloft platform, while the Drift component remains disabled. The incident highlights the potential fallout of third-party application integrations, particularly with popular tools such as Salesloft and Drift.
조사 후 Salesforce는 Salesloft 플랫폼과의 통합을 복원했으며 드리프트 구성 요소는 비활성화되었습니다. 이 사건은 특히 Salesloft 및 Drift와 같은 인기있는 도구와 함께 제 3 자 애플리케이션 통합의 잠재적 낙진을 강조합니다.
What's Next?
다음은 무엇입니까?
The investigation into the Salesloft Drift breach is ongoing. Expect further disclosures and analysis as more details emerge. In the meantime, take this as a learning opportunity to bolster your own security defenses.
Salesloft 드리프트 위반에 대한 조사가 진행 중입니다. 자세한 내용은 더 자세한 내용이 등장 할 때 추가 공개 및 분석이 예상됩니다. 그 동안, 이것을 자신의 보안 방어를 강화할 수있는 학습 기회로 가져 가십시오.
So, yeah, maybe double-check those third-party app permissions? Just a thought. Stay safe out there, folks!
그렇습니다. 아마도 타사 앱 권한을 두 번 확인할 수 있습니까? 그냥 생각. 안전하게 지내세요!
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































