Last seen August 27, 2025

Amazon AWS Supply-Chain Compromise

Evidence indicates that Amazon AWS is affected by a supply-chain compromise.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that Amazon AWS is affected by a supply-chain compromise.

Why This Matters

The evidence matters to defenders using Amazon AWS because it may place downstream environments at risk through compromised dependencies.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether Amazon AWS is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Aug 27, 2025 05:30

Last Seen

Aug 27, 2025 05:30

Exploitation status: UNKNOWN

Primary entities:

Amazon AWS AI Agents Data Leakage Remote Code Execution Supply Chain

Timeline

  • Incident first seen
    Aug 27, 2025 05:30

    BugSkan first recorded this incident.

  • Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data - The Hacker News
    Aug 27, 2025 05:30

    thehackernews.com · Data Leak

Sources

Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data - The Hacker News

thehackernews.com · Aug 27, 2025 05:30

Threat actor UNC6395 exploited compromised OAuth and refresh tokens associated with the Drift AI chat agent, accessible via Salesloft, to gain unauthorized access to Salesforce customer instances. This systematic campaign led to the exfiltration of sensitive data, including AWS access keys, passwords, and Snowflake tokens, from over 700 organizations, indicating a potential supply chain attack.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence