Skip to content

Threat Intel Content Update: 9/10/2025

  • September 10, 2025

SaaS Data Theft Attack Update

Threat Profiles & Threat Objects

  • “Trending & Emerging Threats” weekly update: SaaS Data Theft Attack Update

    • In our August 28 update, we highlighted a new Campaign object covering “widespread data theft” activity impacting Salesforce integrations with Salesloft Drift AI chat technology. 

    • We updated the object following the release of additional technical details, and are featuring it in this week’s Threat Profile update.

    • Responders indicated that the scope of the attack was almost certainly wider than initially indicated, impacting a wide range of integrations with the Drift platform, not just the Salesforce one.

  • Large-scale supply chain compromise: New Campaign object added covering the npm JavaScript package compromises making headlines this week.

    • The incident received attention due to its potential scale (in total, the affected packages account for more than two billion downloads per week), although it was relatively quickly identified and contained.
Data-Driven Threat-Informed Defense

Meet Tidal Enterprise Edition

Quickly and easily develop custom threat profiles and defensive stacks, see your coverage and identify gaps and redundancies, and get daily recommendations to improve your cybersecurity posture.