September 24, 2025 // Data Leak | #OAuth token #Supply Chain Attack #GitHub compromise

Domino Effect: How One Vendor's AI App Breach Toppled Giants - TrendMicro

An OAuth token stolen from a compromised GitHub repository of AI chatbot vendor Salesloft-Drift was leveraged to access their high-privilege Drift account. This enabled a supply chain attack, exfiltrating customer conversation data and contact information from over 700 organizations' Salesforce instances.


Source: Original Report ↗
← Back to Feed