Перейти к содержимому

ALL ACCESS ATTACK | One Chatbot Hacked. 700+ Companies Hit. – EP 20 The CISO Signal

The CISO Signal и Cloudflare

0:00 / 0:00

ALL ACCESS ATTACK | One Chatbot Hacked. 700+ Companies Hit. – EP 20 The CISO Signal

20 003 просмотра · 2 дня назад
The CISO Signal и Cloudflare
20 003 просмотра · 2 дня назад
It was just a little chat window in the corner of the screen. The kind you see on thousands of websites every day. But behind it was a web of trusted connections reaching deep inside the enterprise. In August 2025, attackers tracked as UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration, turning trusted connections to customer Salesforce environments into an attack path reaching hundreds of companies, including some of the world’s most sophisticated technology and cybersecurity organizations. Instead of breaching those companies one by one, the attackers compromised trust upstream and inherited access downstream. Then they went looking for more. Inside stolen Salesforce data, the attackers reportedly searched for passwords, API keys, cloud credentials, and other secrets that could potentially open the next system, cloud environment, or application. The Drift breach exposed a much larger problem. Modern enterprises depend on thousands of connections between SaaS platforms, APIs, cloud services, applications, and third parties. Every connection creates business value, but it also extends trust and expands the attack surface. What happens when something you trust becomes the attacker’s way in? In this episode of The CISO Signal | True Cybercrime Podcast, host Jeremy Ladner is joined by Volker Rath, Field CISO APAC at Cloudflare, the sponsor of this episode, to investigate the Drift breach and what it reveals about the changing enterprise attack surface. Together they explore: • How UNC6395 turned compromised OAuth tokens into an attack path reaching hundreds of companies • Why compromising one trusted integration can create a massive downstream blast radius • What the attackers were searching for inside stolen Salesforce data • How security teams detect malicious behavior hiding behind legitimate access • Why even sophisticated cybersecurity companies can inherit risk from trusted connections • Whether traditional third-party risk programs adequately measure that risk • Why revoking compromised tokens may only be the beginning of incident response • How AI could help attackers learn, adapt, and operate at machine speed • Which assumptions about trusted applications and authorized connections CISOs may need to rethink Your attack surface no longer ends at the edge of your network. It extends through everything you trust. 🎙 This episode is sponsored by Cloudflare. Cloudflare helps organizations connect and protect their people, applications, infrastructure, and networks across an increasingly distributed digital environment. 🌐 https://www.cloudflare.com 🎙 Guest Co-Host Volker Rath Field CISO APAC | Cloudflare Volker works with security leaders and executives across the Asia-Pacific region on the changing realities of enterprise cybersecurity. In this episode, he joins Jeremy to examine what the Drift breach can teach CISOs about inherited trust, third-party risk, and protecting an enterprise increasingly connected to systems outside its direct control. 🔎 Episode Topics: • Salesloft Drift breach • UNC6395 • Salesforce security • OAuth token compromise • SaaS security • Third-party risk • Supply chain attacks • API and cloud security • Identity security • Zero Trust • Enterprise attack surface • AI-powered cyberattacks • Cloudflare • CISO leadership 🧩 The CISO Signal links: ▶️ / @thecisosignal 💼 / the-ciso-signal 🌐 https://www.thecisosignal.com 👥 Join the Conversation: If one of your organization’s trusted applications were compromised tomorrow, would your security team recognize when legitimate access had become malicious access? Let us know what you think in the comments. #CISOSignal #DriftBreach #Salesloft #Salesforce #UNC6395 #OAuth #SaaSSecurity #ThirdPartyRisk #CloudSecurity #IdentitySecurity #ZeroTrust #CyberSecurity #Cloudflare #CISO #TrueCybercrime