Friday, 21 Aug 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > How attackers hit 700 organizations through CX platforms your SOC already approved
Tech and Science

How attackers hit 700 organizations through CX platforms your SOC already approved

Last updated: February 19, 2026 3:15 pm
Share
How attackers hit 700 organizations through CX platforms your SOC already approved
SHARE

CX platforms are revolutionizing customer experience by processing billions of unstructured interactions every year. From survey forms to social media feeds, these platforms use AI engines to automate workflows that touch various systems like payroll, CRM, and payment systems. However, a significant security gap exists in ensuring the integrity of the data being fed into these AI engines, allowing attackers to exploit vulnerabilities and cause widespread damage without deploying any malware.

The Salesloft/Drift breach in August 2025 serves as a stark example of this security loophole. Attackers compromised Salesloft’s GitHub environment, stole Drift chatbot OAuth tokens, and gained access to Salesforce environments across over 700 organizations, including major companies like Cloudflare, Palo Alto Networks, and Zscaler. They then scanned the stolen data for sensitive information like AWS keys, Snowflake tokens, and plaintext passwords, all without deploying any malware.

Despite the prevalence of data loss prevention (DLP) programs in organizations, only a mere 6% have dedicated resources to monitor and secure the data flowing into AI engines. This lack of oversight leaves organizations vulnerable to attacks that exploit legitimate access routes rather than traditional malware-based intrusions. Cloud intrusions have surged by 136% in the first half of 2025, highlighting the urgent need for improved security measures.

Experience management platforms like Qualtrics, which process billions of interactions annually, are no longer just ‘survey tools’ but integral components that connect to critical systems like HRIS, CRM, and compensation engines. Organizations must prioritize input integrity as AI technology becomes increasingly embedded in their workflows to prevent data breaches and unauthorized access.

See also  Daniel H. Wilson on Finding a Native Take on Traditional Alien Invasion Stories

Security leaders have identified six key blind spots that exist between the security stack and the AI engine in CX platforms:

1. DLP tools struggle to detect unstructured sentiment data leaving through standard API calls.
2. Zombie API tokens from past campaigns remain active, posing a security risk.
3. Public input channels lack bot mitigation, allowing fraudulent data to reach the AI engine undetected.
4. Compromised CX platforms enable lateral movement through approved API calls.
5. Non-technical users often hold admin privileges that go unchecked.
6. Open-text feedback containing sensitive information hits the database before PII gets masked, exposing vulnerabilities.

To address these vulnerabilities, organizations must implement continuous monitoring of user activity, configurations, and data access within experience management platforms. Security teams are exploring solutions like extending SSPM tools, API security gateways, and CASB-style access controls to enhance security measures in CX platforms.

By bridging the gap between security posture management and the CX layer, organizations can gain real-time visibility into potential threats and enforce policies to protect sensitive data effectively. It is crucial for security teams to prioritize the security of AI-driven workflows to prevent costly data breaches and ensure the integrity of business decisions made based on AI-generated insights.

TAGGED:ApprovedAttackershitorganizationsPlatformsSOC
Share This Article
Twitter Email Copy Link Print
Previous Article Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect
Next Article Harris Reed Fall 2026 Ready-to-Wear Collection Harris Reed Fall 2026 Ready-to-Wear Collection
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Popular Posts

The cassette tape made a comeback in 2025 thanks to a DNA upgrade

The DNA tape can store vastly more information than a standard cassetteJiankai Li et al.…

December 30, 2025

Authorizing Bridger Pipeline Expansion LLC to Construct, Connect, Operate, and Maintain Pipeline Facilities at the International Boundary at Phillips County, Montana, Between the United States and Canada – The White House

Under the authority given to me as President of the United States, I grant this…

April 30, 2026

This Is the Summer of Celebrity It-Bag Revivals

Fashion trends are constantly evolving, but one thing remains true: what goes around comes around.…

July 20, 2025

Denver-based CEO acquires e-commerce brands after stepping down

Former CEO Jonathan Czaja Acquires The Pro’s Closet, Freebird, and Jane Jonathan Czaja, who recently…

December 13, 2025

Most women get uterine fibroids. This researcher wants to know why

Moore and her team are using hydrogels to recreate the 3-D environment of the uterus…

October 30, 2025

You Might Also Like

How Digital Twins Transform Product Development
Tech and Science

How Digital Twins Transform Product Development

August 21, 2026
Jennifer Lawrence And Steven Spielberg Hit In Huge Celebrity Data Hack
Celebrities

Jennifer Lawrence And Steven Spielberg Hit In Huge Celebrity Data Hack

August 21, 2026
Senator asks US government watchdog to review how feds use hacking tools
Tech and Science

Senator asks US government watchdog to review how feds use hacking tools

August 21, 2026
America’s First Legal Psilocybin Program Treated 346 People. Here’s What Happened. : ScienceAlert
Tech and Science

America’s First Legal Psilocybin Program Treated 346 People. Here’s What Happened. : ScienceAlert

August 21, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?