市值: $2.1828T -0.51%
成交额(24h): $62.8559B -3.16%
  • 市值: $2.1828T -0.51%
  • 成交额(24h): $62.8559B -3.16%
  • 恐惧与贪婪指数:
  • 市值: $2.1828T -0.51%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

OAuth,SaaS供应链和安全风险:导航雷区

2025/09/26 00:40

SalesLoft/Drift Breach突出了SaaS供应链中不断增长的安全风险,尤其是关于Oauth集成。了解如何减轻这些威胁。

OAuth,SaaS供应链和安全风险:导航雷区

The recent Salesloft/Drift breach, which came to light in August 2025, serves as a stark reminder of the lurking dangers within the SaaS ecosystem. Specifically, the exploitation of OAuth integrations has exposed a significant blind spot in SaaS security.

最近在2025年8月揭露的最近的销售楼/漂流违规行为,这引起了SaaS生态系统中潜伏的危险的明显提醒。具体而言,对Oauth集成的开发已经在SaaS安全中揭示了一个很大的盲点。

OAuth: A Double-Edged Sword

Oauth:双刃剑

OAuth, intended to simplify identity and integration, has inadvertently become a major vulnerability. As Jaime Blasco, CTO of Nudge Security, points out, once attackers gain control of OAuth tokens, traditional security measures like multi-factor authentication (MFA) become useless. These tokens grant persistent trust, allowing attackers to move laterally across interconnected SaaS environments. The Drift breach allowed attackers to access Salesforce and Google Workspace environments across hundreds of organizations.

旨在简化身份和集成的Oauth无意中成为一个主要漏洞。正如Audge Security的首席技术官Jaime Blasco指出的那样,一旦攻击者获得了Oauth代币的控制,多因素身份验证(MFA)等传统的安全措施就变得毫无用处。这些令牌授予持续信任,使攻击者能够在互连的SaaS环境中横向移动。漂移漏洞使攻击者能够访问数百个组织的Salesforce和Google Workspace环境。

The Anatomy of the Drift Breach

漂移破裂的解剖结构

The attack, attributed to UNC6395 (aka GRUB1), began months before its discovery. The attackers initially targeted Drift's GitHub repositories, eventually gaining access to their AWS environment. From there, they stole OAuth tokens for various integrations, including Salesforce and Google Workspace. This access allowed them to sift through Salesforce support cases, seeking customer credentials, a tactic previously observed in breaches involving Okta and Cloudflare.

这次袭击归因于UNC6395(又名GRUB1),始于发现的几个月。攻击者最初以Drift的GitHub存储库为目标,最终访问其AWS环境。从那里,他们偷走了Oauth代币进行各种集成,包括Salesforce和Google Workspace。这种访问使他们能够通过Salesforce支持案例进行筛选,寻求客户凭证,这是一种先前在涉及Okta和Cloudflare的违规行为中观察到的策略。

Missed Detection Opportunities

错过检测机会

A key takeaway from the incident is the importance of proactive security measures. Blasco emphasizes that vendors can implement detection mechanisms to identify and prevent token misuse. However, many companies fail to forward SaaS logs, restrict OAuth token lifespans, or enforce session timeouts, leaving their integrations exposed.

事件的关键要点是主动安全措施的重要性。 Blasco强调,供应商可以实施检测机制来识别和防止令牌滥用。但是,许多公司未能转发SaaS日志,限制Oauth代币寿命或执行会话超时,从而使集成均暴露出来。

The SaaS Security Triad of Mistakes

SaaS安全三合会的错误

Blasco identifies three common errors that expose IT and security teams to risk:

Blasco确定了三个常见的错误,使IT和安全团队面临风险:

  1. Lack of visibility into SaaS applications
  2. Inadequate monitoring of integrations
  3. Failure to configure SaaS applications securely

These oversights create a fragmented SaaS landscape ripe for exploitation.

这些疏忽创造了零散的SaaS景观,以剥削。

Shadow SaaS and the Rise of Shadow AI

影子SaaS和影子AI的崛起

The problem is compounded by the rise of shadow SaaS and shadow AI. Employees are increasingly adopting tools outside of IT's purview, often exposing sensitive data to unvetted startups. As AI agents become more sophisticated, they will rely on OAuth, API keys, and other protocols to access data, further expanding the attack surface.

Shadow SaaS和Shadow AI的崛起使问题更加复杂。员工越来越多地采用其范围之外的工具,通常会将敏感数据暴露于未经审查的初创公司。随着AI代理变得越来越复杂,他们将依靠OAuth,API密钥和其他协议来访问数据,从而进一步扩大攻击表面。

Practical Steps for Security Teams

安全团队的实用步骤

Despite the complexity, Blasco advises teams to focus on the fundamentals:

尽管很复杂,但布拉斯科建议团队专注于基本面:

  • Inventory all applications.
  • Enforce MFA.
  • Configure integrations with timeouts and IP restrictions.

Salesforce's Response

Salesforce的回应

Following the breach, Salesforce temporarily disabled all Salesloft integrations as a precautionary measure. Salesloft also took Drift temporarily offline to review the application and enhance its security.

违反后,Salesforce暂时禁用所有SalesLoft集成作为预防措施。 Salesloft还暂时脱机,以审查应用程序并提高其安全性。

Fiji's Crypto Ban: A Different Kind of Security

斐济的加密禁令:另一种安全性

While the SaaS breaches highlight one type of security risk, the island nation of Fiji is taking a different approach to security by renewing its ban on cryptocurrencies. Citing concerns about money laundering, terrorism funding, and a lack of regulatory resources, Fiji aims to protect its financial system and national security. This move, while controversial, reflects a growing awareness of the potential risks associated with digital assets.

尽管Saas违反了一种安全风险,但斐济岛国家通过更新对加密货币的禁令采取了不同的安全方法。斐济援引对洗钱,恐怖主义资金和缺乏监管资源的担忧,旨在保护其金融体系和国家安全。这一举动虽然有争议,但反映了人们对与数字资产相关的潜在风险的越来越多。

Looking Ahead

展望未来

The Salesloft/Drift breach is a wake-up call. The security of the SaaS supply chain requires constant vigilance, robust security practices, and a proactive approach to identifying and mitigating risks. Otherwise, OAuth will continue to be a weak spot. It is the gift that keeps on giving... to hackers, that is.

SalesLoft/Drift Breach是一个警钟。 SaaS供应链的安全需要持续的警惕,强大的安全惯例以及积极的识别和减轻风险的方法。否则,Oauth将继续成为一个弱点。这是不断捐赠给黑客的礼物。

原文来源:petri

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月01日 发表的其他文章