Tech News
← Home  ·  All topics

Salesloft Drift

1 GoKawiil brief on this topic

Report: browser-based SaaS attacks slip past EDR tools, NordLayer finds

NordLayer, citing its Browser Security Report 2026, says attackers increasingly compromise SaaS accounts via browser sessions—OAuth token theft, adversary-in-the-middle phishing, malicious extensions—without triggering endpoint detection and response (EDR) alerts because no malicious process or executable touches the host. It cites the 2025 Salesloft Drift breach, where group UNC6395 used stolen OAuth tokens to pull data from Salesforce via API calls, and a 2026 Microsoft-tracked campaign by Storm-2755 using search ads to phish Canadian employees. NordLayer's report found browser access present in all 504 reviewed applications, with 79% accessible only via browser.