Author: luxovius

  • The Silent Breach: Why Stolen Tokens Are More Dangerous Than Stolen Passwords

    In our previous briefings, we dissected the campaigns of UNC6040’s vishing attacks and UNC6395’s supply chain compromise. The common thread weaving through these devastating breaches wasn’t a software zero-day or a brute-forced password; it was the abuse of a legitimate, fundamental component of the modern cloud: the OAuth token.

    This isn’t a problem limited to a few threat actors. Throughout 2024 and 2025, a wave of attacks has exploited the core logic of OAuth, allowing adversaries to bypass MFA and breach major corporations like Google, Allianz Life, and Louis Vuitton by tricking users into authorising malicious applications. The attackers don’t need to break in when they can be invited in through a legitimate, token-based handshake.

    This is the threat of the OAuth Replay Attack. It’s an attack on the very architecture of trust that connects our cloud applications. To defend against it, you must understand that the target isn’t just your password; it’s the digital key that the password unlocks.

    (more…)
  • One Breach, Many Victims: How the UNC6395 Attack Exposed the SaaS Supply Chain

    In the modern enterprise, third-party apps are the engines of productivity. We integrate them into our core platforms, such as Salesforce, granting them trusted access to our data to streamline workflows. But what happens when the keys to one of those trusted partners fall into the wrong hands?

    A threat actor tracked as UNC6395 recently provided a devastating answer. In a sophisticated supply chain attack that impacted over 700 organizations, the group compromised the Salesloft “Drift” integration, stealing its OAuth tokens. They then used these tokens to access the Salesforce environments of multiple downstream customers, exfiltrating data at scale. High-profile cybersecurity and tech companies, including Cloudflare, Zscaler, Palo Alto Networks, and SpyCloud, have all publicly confirmed being impacted by this widespread campaign.

    As Google’s Threat Intelligence Group first reported, this was not a breach of Salesforce itself. Instead, it was a masterful exploitation of the web of trust that underpins the entire SaaS ecosystem. One of the victims, Cloudflare, publicly detailed its response, confirming that the actor accessed its Salesforce “Case” objects between August 12-17, 2025, providing a rare public glimpse into the impact of such a compromise.

    (more…)
  • From Vishing to Breach: Deconstructing the Salesforce Social Engineering Campaign

    The phone rings. The caller ID might be blocked, or it might be cleverly spoofed to look internal. On the other end is a polite, knowledgeable, and helpful person claiming to be from your IT department. They need your help to install a critical “Data Loader” utility or a system update in Salesforce. They sound legitimate. They sound urgent.

    This is the opening move of a sophisticated attack by a threat group tracked as UNC6040. In this threat briefing, we’ll dissect how this group turns a simple phone call into a full-scale CRM data breach, not by hacking Salesforce, but by hacking the trust of your employees.

    This isn’t a vulnerability in the Salesforce platform itself; it’s a clever abuse of the legitimate, trusted pathways that make the modern cloud ecosystem work.

    (more…)
  • Information Stealers: The Silent Data Exfiltration Threat

    In today’s hyper-connected digital landscape, organisations face a multitude of cybersecurity threats. While ransomware attacks dominate headlines with their immediate and disruptive impact, a more insidious threat operates in the shadows: information stealers. These specialised forms of malware silently harvest sensitive data from compromised systems, often operating undetected for months or even years before their presence is discovered. By that time, the damage is already done—valuable credentials, financial data, intellectual property, and personal information have been quietly exfiltrated, leaving victims vulnerable to fraud, identity theft, and further network compromise.

    (more…)
  • The Modern Cyber Threat Landscape: Navigating Digital Dangers in 2025

    The digital realm has transformed from a landscape of opportunity into a contested battleground where organizations face an ever-expanding array of sophisticated threats. Today’s cyber threat landscape resembles less a static battlefield and more an evolving ecosystem, constantly adapting and developing new attack methods.

    Understanding this landscape isn’t merely an academic exercise—it’s fundamental to developing effective security strategies. Organizations that maintain a clear picture of the threats they face can make informed decisions about resource allocation, security controls, and risk acceptance. Those who don’t often discover the gaps in their understanding only after a breach has occurred.

    This article examines the modern cyber threat landscape from multiple perspectives: the scale and impact of threats, the actors behind them, prevalent attack techniques, emerging frontiers, and approaches for building organizational resilience. By developing this comprehensive view, security professionals can better navigate the challenges ahead and protect their most critical assets.

    (more…)