The security landscape in September 2025 was defined by high-impact exploits targeting enterprise software and cloud-based service providers. Organizations faced significant risks from both newly disclosed vulnerabilities and ongoing campaigns targeting third-party integrations.
What happened
Palo Alto Networks (September 1, 2025)
Attackers gained unauthorized access to a Palo Alto Networks Salesforce instance by exploiting compromised OAuth tokens originally sourced from a separate incident involving Salesloft Drift. This breach exposed sensitive customer information and internal support cases [9].
Plex (September 8, 2025)
Following a security incident, Plex confirmed that an unauthorized party accessed a subset of customer authentication data. The exposed information included email addresses, usernames, and hashed passwords, forcing the company to mandate a global password reset for its user base [9].
CRMEB and Jasmin Ransomware Vulnerabilities
Security researchers identified multiple critical flaws in widely used software. Jasmin Ransomware (up to 1.0.1) was found to contain a SQL injection vulnerability in /handshake.php (CVE-2025-10387) NVD. Simultaneously, CRMEB (up to 5.6.1) was impacted by several flaws, including improper authorization in the Administrator Password Handler (CVE-2025-10389) NVD and UserAddressServices (CVE-2025-10390) NVD, as well as a server-side request forgery (SSRF) vulnerability in its account services (CVE-2025-10391) NVD.
Why this matters
These incidents demonstrate that even robust enterprise platforms are vulnerable when third-party integrations or administrative functions are misconfigured. When attackers compromise a single point of failure—such as an OAuth token or an administrative API—they can bypass traditional perimeter defenses to exfiltrate sensitive data at scale.
How zero-knowledge changes this
SecureIDsafe’s zero-knowledge architecture is designed to neutralize the impact of such breaches. Because all data is encrypted client-side using AES-256 before it ever reaches the server, a breach of the service provider’s database—like the one experienced by Plex—would yield only useless ciphertext. Since the provider never holds the device-derived keys or the 24-word BIP-39 recovery seed, even a full compromise of the backend infrastructure would not expose user credentials or sensitive information. In the event of an administrative API exploit, the attacker would find no plaintext data to steal, effectively rendering the breach a dead end.
Editor's checklist
EDITOR: Add a screenshot or diagram illustrating the difference between server-side storage and SecureIDsafe's client-side encrypted storage. EDITOR: Verify the current status of the Palo Alto Networks remediation efforts to ensure the advice remains current. EDITOR: Add a personal anecdote or observation regarding the difficulty of managing OAuth tokens in enterprise environments. EDITOR: Confirm if any additional patches for the CRMEB vulnerabilities have been released since the initial disclosure.

