Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:
IPv6:
UpOrDown
Ping
MTR
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc & Sum

Google: Salesloft breach scope expands worldwide

Image © Arstechnica
Google warns that all Salesloft Drift authentication tokens should be treated as compromised after a Workspace breach, revoking used tokens and cutting Drift integration with Workspace while it investigates.

Google has urged users of the Salesloft Drift AI chat agent to assume all tokens linked to the platform are compromised after attackers used credentials to access Google Workspace email accounts. In response, Google revoked the tokens involved in the breaches and disabled Drift’s integration with Workspace accounts as it investigates further, with affected account holders notified.

A Thursday advisory update from Google Threat Intelligence Group says the breach is broader than initially disclosed and is not limited to Salesforce integrations. “We now advise all Salesloft Drift customers to treat any authentication tokens stored in or connected to the Drift platform as potentially compromised.”

Salesloft’s own security guidance page had previously indicated that the breach affected only Drift integrations with Salesforce; Google’s update expands that scope, prompting a rethink of the overall threat surface. The company did not immediately respond to requests for confirmation.

The advisory notes that the scope includes other integrations with Drift beyond Salesforce and that Workspace accounts were affected, underscoring the risk of credential theft across connected apps. Salesforce has also acted, disabling Drift integrations with its Slack and Pardot platforms in response to the sequence of events.

Google recommends that Drift customers review all third‑party integrations, revoke and rotate credentials for connected apps, and investigate for signs of unauthorized access. The company has retained Mandiant to assist with incident response as the investigation continues.

 

Arstechnica

Related News

Nvidia Unveils Tiny Desktop AI Box
West Carolina, GOCare Forge Digital Engagement
OpenAI Trims ChatGPT Political Sway
Wasco Gets $10M Fiber Upgrade
Pixnapping Threat Expands to Android 2FA
Bluepeak Upgrades 25k Customers in SD MN

ISP.Tools survives thanks to ads.

Consider disabling your ad blocker.
We promise not to be intrusive.

Cookie Consent

We use cookies to improve your experience on our site.

By using our site you consent to cookies. Learn more