Текущий статус
Связанные исследования
5- Кампания с токенами Drift сделала согласие OAuth границей ответственности Salesforce
Кампания Salesloft Drift против Salesforce-окружений клиентов стала наглядной демонстрацией проблемы ответственности в современном SaaS: злоумышленнику не нужно было взламывать входную дверь каждого клиента. Он мог использовать OAuth-токены доступа и обновления доверенной интеграции как делегированные полномочия.
Основная статьяОпубликовано 2026-07-10 - Salesforce планирует открыть свой первый центр ИИ в Лондоне
Salesforce, гигант программного обеспечения, отметила, что рынок ИИ в Великобритании к 2035 году превысит 1 трлн долларов.
Основная статьяОпубликовано 2026-05-26 - Salesforce's 2021 DNS outage made global deployment a continuity test
Salesforce said an emergency fix triggered a software issue and a DNS network incident in May 2021. The deeper accountability question is how a globally distributed change, process-restart behavior, recovery dependencies and service-level evidence combined to turn one intervention into a broad continuity failure.
Основная статьяОпубликовано 2026-08-13 - Salesforce's 2019 Pardot permissions incident made recoverable authorization state a continuity obligation
Salesforce's 2019 Pardot permissions incident exposed a hard distinction between restoring a cloud service and restoring confidence in who may do what inside it. The public record supports a careful conclusion: authorization state is operational infrastructure, and continuity is unfinished until that state can be reconstructed, checked, and explained.
Основная статьяОпубликовано 2026-08-13 - Salesforce's Drift-token campaign made OAuth consent an accountability boundary
The Salesloft Drift campaign against Salesforce customer environments was a clean demonstration of a modern SaaS accountability problem: the attacker did not need to break the front door of every customer. The attacker could use a trusted integration's OAuth access and refresh tokens as delegated authority. That made consent, scopes, token storage, app marketplace governance, customer log visibility, and third-party incident response part of Salesforce accountability even though the public record says the issue did not stem from a vulnerability in Salesforce's core platform.
Основная статьяОпубликовано 2026-07-10
