{"id":5470,"date":"2025-09-05T09:01:43","date_gmt":"2025-09-05T09:01:43","guid":{"rendered":"https:\/\/signmycode.com\/blog\/?p=5470"},"modified":"2025-09-05T09:01:44","modified_gmt":"2025-09-05T09:01:44","slug":"salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","status":"publish","type":"post","link":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","title":{"rendered":"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">An important supply chain incident has rocked the security industry by showing us that some of the biggest security enterprises are also threatened by the risk of third-party SaaS product integrations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>The incident,<\/em><\/strong> involving Salesloft Drift, a marketing automation solution integrated with Salesforce, resulted in the threat actor getting OAuth tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These tokens allowed them to exfiltrate massive volumes of sensitive data about customers, including account records, case information, and contact data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Some recent victims of the incident were considerable companies<\/strong>; Zscaler and Palo Alto Networks, which are two of the world&#8217;s leading cybersecurity organizations that enterprises rely on to protect their systems around the world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When considered as a supply chain incident, this episode highlights the growing risks of the interconnectedness of SaaS applications and services, where if one application is compromised, it could affect many hundreds of organizations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-attack-what-happened\"><a><\/a>The Attack: What happened<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Between August 8 &#8211; 18, 2025<\/strong>, threat actor UNC6395 exploited the Salesloft Drift Salesforce integration. By stealing OAuth and refresh tokens associated with compromised accounts, the threat actor had persistent access to the victim&#8217;s Salesforce environment at the API level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They were able to exfiltrate a large volume of sensitive data, including account records, cases, and contacts, using the stolen tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Google Threat Intelligence Group (GTIG) and Mandiant confirmed<\/em><\/strong> the scale of the campaign and told all Drift users that they should treat any tokens issued from Drift as vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Part of the severity of the risk assessment was based upon Salesforce&#8217;s decision to temporarily disable all Salesloft integrations until the investigation could continue without jeopardizing further customer exploits.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-impact-on-palo-alto-networks\"><a><\/a>Impact on Palo Alto Networks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Palo Alto Networks confirmed that the breach was isolated to its CRM platform. <strong>Exposed data included:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Business contact information<\/li>\n\n\n\n<li>Internal sales account records<\/li>\n\n\n\n<li>Basic customer case data<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The organization highlighted that its products, services, or systems were not compromised. Palo Alto&#8217;s threat intelligence team, Unit 42, provided further detail, finding that attackers had scanned the stolen data for credentials and had used anti-forensics techniques to try to cover their traces (e.g., deleting queries).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Palo Alto is directly notifying customers that this incident may have affected them and, importantly, noting that the risk may be greater for customers who had stored sensitive credentials in Salesforce case notes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-impact-on-zscaler\"><a><\/a>Impact on Zscaler<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Zscaler disclosed on August 30 that it, too, was impacted by the Drift compromise. <strong>Attackers were able to access Salesforce data that included:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Names, emails, phone numbers, job titles, and regional details<\/li>\n\n\n\n<li>Product licensing and commercial information<\/li>\n\n\n\n<li>Contents of support cases in plaintext<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>CISO Sam Curry stated that <\/em><\/strong>Zscaler&#8217;s products and infrastructure were not compromised, but that many customers were impacted. Zscaler characterized its disclosure as a matter of transparency and encouraged customers to stay alert for any potential misuse.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cloudflare-s-contrasting-response\"><a><\/a>Cloudflare&#8217;s Contrasting Response<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While not included in every report, <strong><em>Cloudflare also confirmed exposure<\/em><\/strong> and came off with a vastly different and notably transparent response. Rather than Palo Alto and Zscaler emphasizing isolation from core systems, Cloudflare took accountability for using third-party tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>The company admitted openly that<\/em><\/strong> it could be at risk for customer logs, tokens, and even passwords shared through Salesforce support tickets. Experts commended this transparency and noted that<strong><em> <\/em><\/strong>this was the model of accountability in response to a breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/github-supply-chain-attack-expose-secrets-across-218-repositories\">GitHub Supply Chain Attack: CVE-2025-30066 and CVE-2025-30154 Expose Secrets Across 218 Repositories<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-expert-reactions\"><a><\/a>Expert Reactions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Industry experts provided broader implications:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Flavio Villanustre, LexisNexis Risk Solutions: <\/strong>Pointed out that breaches mentioned in Zscaler and Palo Alto were extremely concerning for organizations, as they were both in the authentication loop for customer access.<\/li>\n\n\n\n<li><strong>Cory Michal, AppOmni:<\/strong> Praised Cloudflare for setting a new level of transparency in handling <a href=\"https:\/\/signmycode.com\/blog\/software-supply-chain-attacks-notable-examples-and-prevention-strategies\">Supply Chain incidents<\/a> in SaaS usage.<\/li>\n\n\n\n<li><strong>Erik Avakian, Info-Tech:<\/strong> Recommended organizations not only to incorporate Zero Trust principles in SaaS management but also to rotate and revoke OAuth tokens that are no longer used.<\/li>\n\n\n\n<li><strong>Will Townsend, Moor Insights &amp; Strategy: <\/strong>Related the attack to the future risk in agentic AI ecosystems, where the multiplicity of integrations on the API level would be enormous.<\/li>\n\n\n\n<li><strong>Paddy Harrington, Forrester:<\/strong> Noted that &#8220;another day, another OAuth token attack&#8221; and referred to long-standing misconfiguration risks in SaaS.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-risks-to-customers\"><a><\/a>Risks to Customers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Although the vendors demonstrated a limited scope of customers they support, the risks to end customers are far more severe:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Credential Exposure: <\/strong>Customers storing passwords in Salesforce case notes.<\/li>\n\n\n\n<li><strong>Targeted Phishing: <\/strong>Attackers do<strong> <\/strong>not have validated contact information for the organization; future scams and phishing will become much more convincing.<\/li>\n\n\n\n<li><strong>Downstream Impact: <\/strong>There are hundreds of organizations impacted beyond only Zscaler and Palo Alto due to their shared integrations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>As Forrester\u2019s Harrington said<\/strong>, the hard work is just beginning: customers will need to sift through their records to understand what they have been exposed to, and then prepare for follow-on attacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-defensive-measures\"><a><\/a>Defensive Measures<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security teams should act now to mitigate consequences:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Revoke and rotate all OAuth tokens tied to Drift.<\/li>\n\n\n\n<li>Audit Salesforce logs, identity provider logs, and API activity for anomalies.<\/li>\n\n\n\n<li>Monitor for social engineering attempts leveraging exfiltrated sales and customer data.\u00a0<\/li>\n\n\n\n<li>Apply Zero Trust principles: Treat all SaaS apps as external networks; enforce token expiration; periodically review contracts with third-party vendors.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-broader-implications-for-saas-security\"><a><\/a>Broader Implications for SaaS Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This incident reveals a disturbing truth: cybersecurity firms are at risk when their SaaS ecosystems are breached. <strong>It demonstrates:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The fragility of <a href=\"https:\/\/signmycode.com\/blog\/what-is-software-supply-chain-security-comprehensive-guide\">supply chain security<\/a> in SaaS environments.<\/li>\n\n\n\n<li>The growing need for <a href=\"https:\/\/signmycode.com\/blog\/top-11-api-security-best-practices-to-prevent-security-threats\">API security<\/a> as enterprises adopt integrations with AI capabilities.<\/li>\n\n\n\n<li>The need for vendor transparency, with Cloudflare&#8217;s response being a gold standard.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-protect-against-supply-chain-attacks\">How to Protect Against Supply Chain Attacks?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Breaches like the Salesloft Drift breach demonstrate exactly why enterprises need to bolster their supply chain security. <strong>A few simple steps can make a difference:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rotate and revoke OAuth tokens frequently to limit persistence if an attacker steals the tokens.<\/li>\n\n\n\n<li>Audit third-party integrations to ensure your SaaS vendors are not only using <a href=\"https:\/\/signmycode.com\/blog\/what-is-software-security-importance-techniques-challenges-and-best-practices\">security best practices<\/a>, but also implementing them correctly.<\/li>\n\n\n\n<li>Implement <a href=\"https:\/\/signmycode.com\/blog\/what-is-a-software-bill-of-material-sbom-and-supply-chain-security\">SBOM<\/a> to identify and resolve potential security risks more effectively.<\/li>\n\n\n\n<li>Implement Zero Trust principles to limit excessive privileges and lateral movement.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">To strengthen software integrity across the supply chain, enterprises can also implement <a href=\"https:\/\/signmycode.com\/digicert-software-trust-manager\">DigiCert Software Trust Manager<\/a>, which provides visibility and control to protect code signing keys, identities, and policies in a centralized platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is to ensure only trusted software is signed and distributed, which addresses one of the most common attack points in supply chain compromises.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An important supply chain incident has rocked the security industry by showing us that some of the biggest security enterprises are also threatened by the risk of third-party SaaS product integrations. The incident, involving Salesloft Drift, a marketing automation solution integrated with Salesforce, resulted in the threat actor getting OAuth tokens. These tokens allowed them&hellip; <a class=\"more-link\" href=\"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\">Read More <span class=\"screen-reader-text\">Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler<\/span><\/a> <\/p>\n","protected":false},"author":1,"featured_media":5472,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,458,457],"tags":[875,874],"class_list":["post-5470","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-code-signing-updates","category-cyber-security","category-developers-guide","tag-salesloft-drift","tag-salesloft-drift-supply-chain-attack","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Salesloft Drift Supply Chain Attack Hits Palo Alto Networks &amp; Zscaler<\/title>\n<meta name=\"description\" content=\"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler\" \/>\n<meta property=\"og:description\" content=\"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\" \/>\n<meta property=\"og:site_name\" content=\"SignMyCode - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-05T09:01:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-05T09:01:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/salesloft-drift-supply-chain-attack.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"453\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\",\"name\":\"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks & Zscaler\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/salesloft-drift-supply-chain-attack.webp\",\"datePublished\":\"2025-09-05T09:01:43+00:00\",\"dateModified\":\"2025-09-05T09:01:44+00:00\",\"description\":\"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/salesloft-drift-supply-chain-attack.webp\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/salesloft-drift-supply-chain-attack.webp\",\"width\":912,\"height\":453,\"caption\":\"Salesloft Drift Supply Chain Attack Incidence\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"name\":\"SignMyCode - Blog\",\"description\":\"Code Signing News, Updates\",\"publisher\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\",\"name\":\"SignMyCode.com\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"width\":135,\"height\":86,\"caption\":\"SignMyCode.com\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks & Zscaler","description":"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","og_locale":"en_US","og_type":"article","og_title":"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler","og_description":"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.","og_url":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","og_site_name":"SignMyCode - Blog","article_published_time":"2025-09-05T09:01:43+00:00","article_modified_time":"2025-09-05T09:01:44+00:00","og_image":[{"width":912,"height":453,"url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/salesloft-drift-supply-chain-attack.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","url":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler","name":"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks & Zscaler","isPartOf":{"@id":"https:\/\/signmycode.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage"},"image":{"@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage"},"thumbnailUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/salesloft-drift-supply-chain-attack.webp","datePublished":"2025-09-05T09:01:43+00:00","dateModified":"2025-09-05T09:01:44+00:00","description":"Recent Supply chain attack hits Salesforce and Salesloft Drift. Customer data exposed as Palo Alto, Zscaler report breaches tied to UNC6395.","breadcrumb":{"@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#primaryimage","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/salesloft-drift-supply-chain-attack.webp","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/salesloft-drift-supply-chain-attack.webp","width":912,"height":453,"caption":"Salesloft Drift Supply Chain Attack Incidence"},{"@type":"BreadcrumbList","@id":"https:\/\/signmycode.com\/blog\/salesloft-drift-supply-chain-attack-hits-palo-alto-networks-and-zscaler#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/signmycode.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Salesloft Drift Supply Chain Attack Hits Palo Alto Networks and Zscaler"}]},{"@type":"WebSite","@id":"https:\/\/signmycode.com\/blog\/#website","url":"https:\/\/signmycode.com\/blog\/","name":"SignMyCode - Blog","description":"Code Signing News, Updates","publisher":{"@id":"https:\/\/signmycode.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/signmycode.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/signmycode.com\/blog\/#organization","name":"SignMyCode.com","url":"https:\/\/signmycode.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","width":135,"height":86,"caption":"SignMyCode.com"},"image":{"@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/comments?post=5470"}],"version-history":[{"count":1,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5470\/revisions"}],"predecessor-version":[{"id":5471,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5470\/revisions\/5471"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media\/5472"}],"wp:attachment":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media?parent=5470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/categories?post=5470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/tags?post=5470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}