当前状态
相关研究
5- Salesforce Drift 令牌事件将 OAuth 授权变成了问责边界
Salesloft Drift 攻击 Salesforce 客户环境的事件,清晰地展示了现代 SaaS 问责问题:攻击者无需攻破每个客户的前门,而是可以利用可信集成的 OAuth 访问令牌和刷新令牌作为代理授权。这使得同意、作用域、令牌存储、应用市场治理、客户日志可见性以及第三方事件响应都成为 Salesforce 问责的一部分,尽管公开记录表明该问题并非源于 Salesforce 核心平台的漏洞。
主文章发布时间 2026-07-10 - Salesforce 计划在伦敦设立首个 AI 中心
软件巨头 Salesforce 指出,英国 AI 市场预计到 2035 年将增长至超过 1 万亿美元。
主文章发布时间 2026-05-26 - Salesforce's 2021 DNS outage made global deployment a continuity test
Salesforce said an emergency fix triggered a software issue and a DNS network incident in May 2021. The deeper accountability question is how a globally distributed change, process-restart behavior, recovery dependencies and service-level evidence combined to turn one intervention into a broad continuity failure.
主文章发布时间 2026-08-13 - Salesforce's 2019 Pardot permissions incident made recoverable authorization state a continuity obligation
Salesforce's 2019 Pardot permissions incident exposed a hard distinction between restoring a cloud service and restoring confidence in who may do what inside it. The public record supports a careful conclusion: authorization state is operational infrastructure, and continuity is unfinished until that state can be reconstructed, checked, and explained.
主文章发布时间 2026-08-13 - Salesforce's Drift-token campaign made OAuth consent an accountability boundary
The Salesloft Drift campaign against Salesforce customer environments was a clean demonstration of a modern SaaS accountability problem: the attacker did not need to break the front door of every customer. The attacker could use a trusted integration's OAuth access and refresh tokens as delegated authority. That made consent, scopes, token storage, app marketplace governance, customer log visibility, and third-party incident response part of Salesforce accountability even though the public record says the issue did not stem from a vulnerability in Salesforce's core platform.
主文章发布时间 2026-07-10
