
Attackers Breach 700 Orgs via CX Platforms
Attackers exploited Salesloft’s GitHub compromise to steal Drift OAuth tokens, accessing Salesforce in 700+ organizations like Cloudflare and Zscaler without malware. They poisoned unstructured CX data ingested by AI engines, triggering workflows to payroll and CRM. Security blind spots include DLP missing sentiment data and persistent zombie API tokens.




