By the CyberWire staff
Top Stories.
- Security firms affected by Salesloft Drift breach.
- Extortion group claims responsibility for Jaguar Land Rover attack.
- China's Salt Typhoon campaign may have impacted every American.
- TamperedChef spreads via malicious PDF editor tools.
- Amazon shuts down APT29 watering-hole campaign.
- CISA names Nicholas Andersen as Executive Assistant Director of Cybersecurity.
Security firms affected by Salesloft Drift breach.
KrebsOnSecurity is tracking the ongoing impact of breaches stemming from the theft of authentication tokens from AI chatbot provider Salesloft. Google's Threat Intelligence Group (GTIG) warned last week that a threat actor had compromised numerous Salesforce instances using the stolen tokens. The researchers then discovered that the hackers had stolen authentication tokens for hundreds of additional services that integrate with Salesloft, including Google Workspace, Slack, Microsoft Azure, Amazon S3, and OpenAI.
Cloudflare, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, Tenable, and Zscaler have confirmed that their Salesforce instances were breached. Zscaler says the threat actor may have accessed customers' business contact information and "[p]lain text content from certain support cases." Palo Alto Networks told BleepingComputer, "The attacker extracted primarily business contact and related account information, along with internal sales account records and basic case data. We are in the process of directly notifying any impacted customers." The company stressed that the incident was confined to its Salesforce environment, and "did not affect any Palo Alto Networks products, systems, or services."
DMV Rising, D.C.’s Premier Conference for Cyber Execs.
The Washington, D.C. Maryland, and Virginia (DMV) region has established itself as a top-tier player in the global cyber industry. Join us on September 18, 2025 to celebrate the remarkable accomplishments of the DMV's cybersecurity community, connect with the brilliant minds shaping the future of the field, and experience firsthand why the DMV region is the beating heart of cyber innovation. Register now to secure your spot.
Extortion group claims responsibility for Jaguar Land Rover attack.
Jaguar Land Rover (JLR) sustained a cyberattack over the weekend that "severely disrupted" its retail and manufacturing operations. The company hasn't disclosed the nature of the attack, but SecurityWeek notes that the company's response suggests ransomware may have been involved. The BBC reports that JLR shut down vehicle production at its two main UK plants following the incident. The BBC points out that the attack took place the day before new registration plates became available on September 1st, which may have been intentional on the part of the attackers. The Telegraph reports that more than a million drivers are unable to get repairs as dealerships cannot obtain parts for Jaguar or Land Rover vehicles.
A criminal collective calling itself "Scattered Lapsus$ Hunters" has claimed responsibility for the attack, according to the BBC. The hackers, who are thought to be English-speaking teenagers, chose the name due to their prior associations with the criminal groups Shiny Hunters, Lapsus$, and Scattered Spider. The group is attempting to extort JLR as they brag about the hack on Telegram. The BBC notes that the UK's National Crime Agency recently arrested four alleged Scattered Spider members accused of hacking M&S, Co-op, and Harrods earlier this year.
China's Salt Typhoon campaign may have impacted every American.
The New York Times reports on the significance of China's Salt Typhoon campaign, noting that the cyberespionage operation may have gathered information on every American. Cynthia Kaiser, the FBI's former Deputy Assistant Director who oversaw an investigation into Salt Typhoon, told the Times that the scope of the campaign was much broader than typical cyberespionage activity. The widespread operation swept up information from "telecommunications, government, transportation, lodging, and military infrastructure networks."
Western allies—including the US, UK, Canada, Finland, Germany, Italy, Japan, and Spain—issued a "name-and-shame" statement on Salt Typhoon last week, linking the activity to several Chinese technology companies that provide services to Beijing's People's Liberation Army and Ministry of State Security.
TamperedChef spreads via malicious PDF editor tools.
Heimdal Security has published a report on a malware campaign targeting European organizations via fake PDF editing tools. The attackers promoted the malicious editing tools with Google Ads and compromised websites, targeting users searching for free alternatives to Adobe tools. Once installed, the fake editors functioned normally for nearly two months before downloading an infostealer dubbed "TamperedChef."
Truesec is also tracking the campaign, noting that the TamperedChef's dormancy period was likely designed to maximize infections before security tools began flagging the malware. The researchers add, "Truesec has observed at least 5 different Google campaign IDs which suggests a widespread campaign. The length from the start of the campaign until the malicious update was also 56 days, which is close to the 60 days length of a typical Google advertising campaign."
Amazon shuts down APT29 watering-hole campaign.
Amazon’s threat intelligence team describes a watering-hole campaign run by APT29, a threat actor tied to Russia's Foreign Intelligence Service (SVR). The threat actor used "compromised websites to redirect visitors to malicious infrastructure designed to trick users into authorizing attacker-controlled devices through Microsoft’s device code authentication flow." Amazon shut down the campaign on AWS infrastructure, then tracked the activity and disrupted it again when the threat actor moved to another cloud provider.
The researchers urge users to follow security best practices and to "[f]ollow Microsoft’s security guidance on device authentication flows and consider disabling this feature if not required."
CISA names Nicholas Andersen as Executive Assistant Director of Cybersecurity.
The US Cybersecurity and Infrastructure Security Agency (CISA) has appointed Nicholas Andersen as Executive Assistant Director of Cybersecurity, CyberScoop reports. Andersen most recently served as President and COO at Invictus International Consulting, and held posts in the Department of Energy’s Cybersecurity, Energy Security, and Emergency Response division under the first Trump administration.
CyberScoop notes that CISA's Executive Assistant Director of Cybersecurity role has "seen swift turnover in the past year," and was previously held by Chris Butera in an acting capacity.