Aktueller Status
Verwandte Forschung
5- Salesforces Drift-Token-Kampagne machte OAuth-Zustimmung zur Rechenschaftsgrenze
Die Salesloft Drift-Kampagne gegen Salesforce-Kundenumgebungen war eine klare Demonstration eines modernen SaaS-Rechenschaftsproblems: Der Angreifer musste nicht die Haustür jedes Kunden aufbrechen. Der Angreifer konnte die OAuth-Zugriffs- und Aktualisierungstokens einer vertrauenswürdigen Integration als delegierte Autorität nutzen.
PrimärartikelVeröffentlicht 2026-07-10 - Salesforce plant erstes KI-Zentrum in London
Salesforce, der Software-Riese, stellte fest, dass der KI-Markt in Großbritannien bis 2035 eine Billion US-Dollar übersteigen wird.
PrimärartikelVeröffentlicht 2026-05-26 - Salesforce's 2021 DNS outage made global deployment a continuity test
Salesforce said an emergency fix triggered a software issue and a DNS network incident in May 2021. The deeper accountability question is how a globally distributed change, process-restart behavior, recovery dependencies and service-level evidence combined to turn one intervention into a broad continuity failure.
PrimärartikelVeröffentlicht 2026-08-13 - Salesforce's 2019 Pardot permissions incident made recoverable authorization state a continuity obligation
Salesforce's 2019 Pardot permissions incident exposed a hard distinction between restoring a cloud service and restoring confidence in who may do what inside it. The public record supports a careful conclusion: authorization state is operational infrastructure, and continuity is unfinished until that state can be reconstructed, checked, and explained.
PrimärartikelVeröffentlicht 2026-08-13 - Salesforce's Drift-token campaign made OAuth consent an accountability boundary
The Salesloft Drift campaign against Salesforce customer environments was a clean demonstration of a modern SaaS accountability problem: the attacker did not need to break the front door of every customer. The attacker could use a trusted integration's OAuth access and refresh tokens as delegated authority. That made consent, scopes, token storage, app marketplace governance, customer log visibility, and third-party incident response part of Salesforce accountability even though the public record says the issue did not stem from a vulnerability in Salesforce's core platform.
PrimärartikelVeröffentlicht 2026-07-10
