Heroes, a detailed look at the current cybersecurity landscape for September 3, 2025.
Critical Threats
High Severity
Executive Briefing
This analysis from a BSides San Francisco 2025 presentation provides a strategic framework for security leaders by categorizing security champions into four distinct 'tribes'. Understanding these different personas can help executives build more effective, tailored, and impactful security champion programs, improving the overall security culture and posture of the organization.
Vendor Spotlight
Spotlight Rationale: Zscaler was named as one of the organizations affected by the recent Salesloft Drift breach, which leveraged exposed credentials within a Salesforce integration. This makes Zscaler's solutions for SaaS Security Posture Management (SSPM) directly relevant to mitigating the critical, real-world threats highlighted in today's intelligence.
Threat Context: When Google Says “Scan for Secrets”: A Complete Guide to Finding Hidden Credentials in Salesforce
Platform Focus: Zscaler for Cloud Protection (ZCP)
Zscaler's SSPM capabilities, part of its broader cloud protection suite, are designed to address the security risks inherent in complex SaaS environments like Salesforce. The platform provides continuous monitoring of SaaS application configurations, permissions, and connected third-party apps. This allows security teams to proactively discover and remediate risks such as exposed secrets, misconfigurations, and excessive user permissions, directly countering the attack vectors used in supply-chain breaches like the one involving Salesloft.
Actionable Platform Guidance: The provided intelligence did not include specific, immediate configuration actions. For detailed implementation and configuration guidance for Zscaler's SaaS Security Posture Management (SSPM) to scan for exposed secrets in Salesforce, please contact Zscaler support or your technical account manager.
Source: securityboulevard.com