This website uses cookies

Read our Privacy policy and Terms of use for more information.

The perimeter didn’t break, yet something deeper did.

A recent breach tied to UNC6395 came through OAuth tokens, quietly riding in on trusted app integrations between Salesloft, Drift, and Salesforce. With hundreds of organizations potentially impacted, the incident goes to show that your SaaS stack also comes with all its connections.

As SaaS ecosystems grow more powerful, they also grow more fragile. Each unseen thread keeps businesses running, but also widens the attack surface.

In this case, access was granted by default, visibility was lost in complexity, and trust was extended just a little too far.

So, do you actually know what’s connected to your SaaS tools right now?

And since we’re talking about trust and complexity, we’re thrilled to welcome back Nudge Security as an affiliate partner of The National CIO Review®. Their work uncovering hidden SaaS links before they surface as problems has never been more timely.

Inside this week’s CSB:

  • DoD CIO nominee is gaining favor in the cyber community.

  • Jaguar Land Rover continues to falter in the wake of major breach.

  • Hackers hit Tiffany & Co., but breakfast wasn’t the only thing they took.

  • Netskope makes noise with one of the year’s biggest cyber IPOs.

P.S. Found us through a friend or stumbled upon us on socials? Subscribe here!💥

FEATURED

The Drift Salesloft Breach: A Wake-up Call for SaaS Supply Chain Security

When news broke that the threat group UNC6395 had infiltrated Salesforce environments by abusing OAuth tokens from the Salesloft Drift connected app, it sent shockwaves through the security community. Keep Reading…

EXTRA BYTES

RESOURCE HUB

The Salesloft Drift incident underscores how fragile and over-trusted today’s web of SaaS and AI integrations has become, and why organizations need to rethink how they secure it.

Nudge Security is the only SaaS security solution that alerts you of breaches impacting your 3rd and 4th party SaaS suppliers, with breach details and recommended actions.  

TRENDING

CYBER REWIND

Harnessing Agentic AI for Cybersecurity While Managing Emerging Risk

THREAT HEATMAP - Week of September 8, 2025

AMPLIFY THE VOICE OF THE CISO!

Subscribers make it possible for your TNCR Crew to curate the latest in technology thought-leadership. To support our work and get unlimited access to our award-winning coverage, subscribe today.

Copyright © . All rights reserved.

Notifications are important to maintain a community that Connects, Collaborates, and Contributes. If you need assistance changing your unsubscribe, please let us know, and we will be happy to assist.

Keep Reading