home.social

#salesloft — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #salesloft, aggregated by home.social.

  1. "The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

    [...]

    In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

    ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

    Read more of Lawrence Abrams' great reporting on Bleeping Computer:
    bleepingcomputer.com/news/secu

    #Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

  2. In late August, hackers gained access to the inner workings of an #AI #Chatbot platform...

    #Drift, a chatbot agent acquired by #Salesloft is popular with American sales and marketing teams

    ...they stole authentication tokens that gave them access to #Salesforce, #GoogleWorkspace, #Slack, #AmazonS3, #MicrosoftAzure, #OpenAI, and potentially any other platform that integrates with Salesloft.

    @protonprivacy
    proton.me/blog/salesloft-drift

  3. #Google warns that mass data theft hitting #Salesloft #AIagent has grown bigger

    Google is advising users of the #SalesloftDriftAI #chat #agent to consider all #security #tokens connected to the platform compromised following the discovery that unknown #attackers used some of the #credentials to access email from #GoogleWorkspace accounts.
    #privacy #security

    arstechnica.com/security/2025/