home.social

#unc6395 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #unc6395, aggregated by home.social.

fetched live
  1. OAuth Grants Expose Hidden Attack Vector in Enterprise Workspaces

    Unmanaged OAuth grants are a ticking time bomb in enterprise workspaces, with 80% of security leaders recognizing them as a critical or significant risk. A recent attack by threat actor UNC6395 exploited valid OAuth refresh tokens to breach Salesforce environments of over 700 organizations, highlighting the devastating…

    osintsights.com/oauth-grants-e

    #OauthSecurityRisk #UnmanagedOauthGrants #RefreshTokenAttacks #Unc6395 #Salesforce

  2. "The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

    [...]

    In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

    ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

    Read more of Lawrence Abrams' great reporting on Bleeping Computer:
    bleepingcomputer.com/news/secu

    #Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

  3. "The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

    [...]

    In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

    ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

    Read more of Lawrence Abrams' great reporting on Bleeping Computer:
    bleepingcomputer.com/news/secu

    #Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

  4. Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion
    #UNC6040 #UNC6395
    ic3.gov/CSA/2025/250912.pdf

  5. Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion
    #UNC6040 #UNC6395
    ic3.gov/CSA/2025/250912.pdf

  6. In 2025, UNC6395 struck Salesloft’s Drift, exposing Salesforce data and Google Workspace emails. From malicious IPs to SOQL queries, learn how this stealth attack unfolded and get Mandiant-backed strategies to lock down your integrations. Protect your business—read the full story now.

    #SecurityLand #BreachBreakdown #Cybersecurity #Salesforce #SalesloftDrift #DataBreach #CyberAttack #UNC6395 #Mandiant

    Read More: security.land/unc6395-stealth-