Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    M4 iPad Pro is given a discount of $ 100 as the last minute Labor Day deal

    September 1, 2025

    IEEE President Note: Protecting the impact of technical history

    September 1, 2025

    ZSCAler Data Brech Slesloft Drift Highlights Customer Information

    September 1, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»ZSCAler Data Brech Slesloft Drift Highlights Customer Information
    Security

    ZSCAler Data Brech Slesloft Drift Highlights Customer Information

    PineapplesUpdateBy PineapplesUpdateSeptember 1, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    ZSCAler Data Brech Slesloft Drift Highlights Customer Information
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ZSCAler Data Brech Slesloft Drift Highlights Customer Information

    Cyber ​​security company ZSCAler warned that the danger actors faced data breeches after the actors of their salesforce institutes and stole the customer information, including the content of support cases.

    This warning follows the salesloft drift agreement, an AI chat agent that integrates with salesforce, in which the attackers stole oauth and refresh tokens, so that customers can get access to the cellsforce environment and exfiltrate sensitive data.

    In a consultant, Zscler says that its salesforce example was influenced by this supply-series attack, highlighting customers’ information.

    “As part of this campaign, unauthorized actors had access to salesloft drift credentials of their customers, including Zscler,” ZSCAler advisor,

    “After a detailed review as part of our ongoing investigation, we have determined that these credentials have allowed limited access to some Zscaler’s salesforce information.”

    Exposed information includes the following:

    • Name
    • Commercial email address
    • Job title
    • phone numbers
    • Regional/location details
    • ZSCAler Product Licensing and Commercial Information
    • Material from some support cases

    The company emphasizes that data breech only affects its salesforce instance and no ZSCAler products, services or infrastructure.

    While Zscler states that he has not misused this information, it recommends that customers be cautious against potential fishing and social engineering attacks that can take advantage of this information.

    The company also says that it has canceled all the salesloft drift integration for its salesforce for example, rotating other API tokens, and investigating the event.

    ZSCAler has also strengthened its customer authentication protocol when responding to the customer aid calls for the guard against social engineering attacks.

    Google Threat Intelligence warned last week that a danger tracked as UnC6395 is behind the attacks, stealing support cases for the authentication tokens, passwords and secrets shared by customers while requesting support.

    “GTIG saw UnC6395 targeting sensitive credentials like Amazon Web Services (AWS) Access Keys (AKIA), password and snowflake-related access tokens,” Reports Google,

    “UNC6395 demonstrated operational safety awareness by removing query jobs, although the logs were not affected and organizations should still review the relevant logs relevant to evidence of data exposure.”

    It was later discovered that the salesloft supply-chain attack not only affected the flow salesforce integration, but also drifted emails, which are used to manage email answers and to organize CRM and marketing automation database.

    Google warned last week that the attackers also used the stolen tokens to reach the Google work area email accounts and read emails as part of this violation.

    Google and Salesforce have temporarily pending their drift integration at the completion of an investigation.

    Some researchers have told bleepingcomputer that they believe the salesloft drift agreement overlaps with the recent salesforce data theft attacks by the SHINYHUNTERS Efferform Group.

    Since the beginning of the year, the actor of the danger has been carrying out social engineering attacks to dissolve the salesforce instance and download the data.

    During these attacks, the danger actors conduct voice phishing to cheat employees to connect a malicious Oauth app with their company’s salesforce instance.

    Once the link was linked, the danger actors used connections to download and steal the database, which was then used to remove the company via email.

    Since Google first reported attacks in June, many data violations are bound by social engineering attacks. Google onlyCisco, Kisan Insurance, Workday, Adidas, Kantas, Allians Life, and LVMH assistants Tiffany & Co.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    Brech customer data Drift Highlights information Slesloft ZSCAler
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleYou can buy an iPhone 16 Pro for $ 250 on Amazon right now – how the deal works
    Next Article IEEE President Note: Protecting the impact of technical history
    PineapplesUpdate
    • Website

    Related Posts

    Security

    M4 iPad Pro is given a discount of $ 100 as the last minute Labor Day deal

    September 1, 2025
    Security

    Angriffe Auf NPM-Lieferkette Gefährden Entwicklungsumgebungen

    September 1, 2025
    Security

    I have tried 3 different smart rings, but I am going back to Apple Watch – Why is here

    September 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    M4 iPad Pro is given a discount of $ 100 as the last minute Labor Day deal

    September 1, 2025

    IEEE President Note: Protecting the impact of technical history

    September 1, 2025

    ZSCAler Data Brech Slesloft Drift Highlights Customer Information

    September 1, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.