Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Dynatrace

Dynatrace Vendor Cyber Rating & Cyber Score

dynatrace.com

Dynatrace keeps today’s AI-driven world working by advancing observability for today’s digital business. The world relies on software, but what isn’t seen is just how much complexity goes on behind the scenes to make sure everything stays up and running. Most businesses today have huge digital ecosystems made up of software, data flows, applications, and hybrid-cloud environments. As these ecosystems grow in complexity, so do the points of failure. Outages and glitches resulting in grounded flights or failed financial transactions prove how critical it is that software works as expected, making AI-powered observability an essential capability to ensure digital businesses run smoothly and recover quickly — keeping the world working.


Dynatrace A.I CyberSecurity Scoring

Dynatrace
Company Information
Website:https://www.dynatrace.com
Employees number:5,885
Number of followers:393,049
NAICS:5112
Industry Type:Software Development
Homepage:dynatrace.com
Dynatrace Risk Score (AI oriented)
Between 700 and 749
logo
DynatraceSoftware Development
Updated:
31/08/2026
704/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Dynatrace Global Score (TPRM)
xxxx
logo
DynatraceSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Dynatrace
DynatraceModerate
Current Score
704Ba (MODERATE)
01000
3 incidents
-29.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
701Before Incident
JULY 2026
696Before Incident
JUNE 2026
692Before Incident
MAY 2026
688Before Incident
APRIL 2026
688Before Incident
MARCH 2026
686Before Incident
FEBRUARY 2026
684Before Incident
JANUARY 2026
684Before Incident
Vulnerability
14 Jan 2026Dynatrace
Node.js and Dynatrace: Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Node.js Critical Security Issue Leading to Denial-of-Service (DoS)

680After Incident
HIGH-4
NODDYN1768467414
Node.js Patches Critical DoS Vulnerability Affecting Widespread Ecosystem Node.js has released urgent security updates to address a critical denial-of-service (DoS) vulnerability (CVE-2025-59466, CVSS 7.5) that could crash nearly all production Node.js applications if exploited. The flaw arises when stack space exhaustion occurs in user code while the `async_hooks` API is enabled, causing Node.js to exit abruptly with an error code (7) instead of throwing a catchable exception. The issue stems from a bug in Node.js’s handling of stack overflows in conjunction with `async_hooks`, a low-level API used to track asynchronous operations. Frameworks and Application Performance Monitoring (APM) tools including React Server Components, Next.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry are affected due to their reliance on `AsyncLocalStorage`, a component built on `async_hooks`. The vulnerability impacts all Node.js versions from 8.x (released in 2017) through 18.x, though only supported LTS and current releases have received patches. Fixed versions include: - Node.js 20.20.0 (LTS) - Node.js 22.22.0 (LTS) - Node.js 24.13.0 (LTS) - Node.js 25.3.0 (Current) End-of-life (EoL) versions (8.x–18.x) remain unpatched. The fix rethrows stack overflow errors to user code rather than treating them as fatal, improving error handling predictability. Node.js acknowledged the fix as a mitigation, citing limitations in the ECMAScript specification and V8’s stance on stack exhaustion. Alongside this flaw, Node.js patched three additional high-severity vulnerabilities (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465) enabling data leakage, symlink-based file reads, and remote DoS attacks. The updates underscore the need for prompt upgrades in affected environments.
INCIDENT DETAILS -
TYPE
Denial-of-Service (DoS)
IMPACT
Systems Affected: Node.js applications using async_hooks or frameworks/tools relying on AsyncLocalStorageDowntime: Potential service unavailability due to process terminationOperational Impact: Denial-of-service leading to service disruptionBrand Reputation Impact: Potential reputational damage due to service outages
DECEMBER 2025
684Before Incident
NOVEMBER 2025
682Before Incident
OCTOBER 2025
680Before Incident
SEPTEMBER 2025
732Before Incident
Breach
25 Sep 2025Dynatrace
Salesloft

AI-Powered Supply Chain Attack via Compromised Salesloft-Drift Integration (2025)

677After Incident
CRITICAL-55
SAL2862828092525
The attack on Salesloft began with the compromise of an internal GitHub repository, where attackers stole a high-privilege OAuth token granting access to its Drift cloud application. Exploiting Drift’s trusted integrations, the attackers pivoted to Salesforce instances of multiple high-profile customers—including Palo Alto Networks, Cloudflare, Zscaler, and Tenable—exfiltrating customer conversation data, contact details, and sensitive business information. The breach exposed a supply-chain vulnerability, where a single compromised AI-powered integration (Drift’s chatbot) enabled mass data theft across 700+ organizations, including cybersecurity leaders. The attackers also harvested OpenAI API credentials, demonstrating the cascading risks of interconnected AI ecosystems. While companies like Okta mitigated damage via IP allow-listing, others faced reputational harm, forensic costs, and erosion of customer trust. The incident highlighted critical gaps in third-party risk management, token security, and AI integration monitoring, with long-term implications for enterprise security postures.
INCIDENT DETAILS -
TYPE
Supply Chain AttackData BreachUnauthorized AccessAI Integration Exploitation
MOTIVATION
Data TheftEspionageFinancial Gain (Potential)Supply Chain Disruption
IMPACT
Customer Conversation DataContact InformationAuthentication Tokens (Including OpenAI API Credentials)Salesforce Instance DataSalesloft GitHub RepositoriesDrift Cloud ApplicationConnected Salesforce InstancesOpenAI API IntegrationsForensic InvestigationsCustomer Trust ErosionIntegration AuditsSecurity Control OverhaulsExpected (Not Quantified)Severe (Especially for Cybersecurity Firms)Loss of Customer TrustIncreased Scrutiny of AI Security PracticesPotential Regulatory FinesContractual Breach ClaimsLitigation RiskHigh (Due to PII in Conversation Data)Low (Not Explicitly Mentioned)
DATA BREACH
Customer Conversation LogsContact InformationAPI CredentialsSalesforce DataHigh (PII, Business Communications, Authentication Tokens)Confirmed (Systematic via Salesforce Integrations)Conversation LogsContact DatabasesAPI TokensPotentially Calendar/Email DataNamesEmail AddressesPotentially Phone NumbersBusiness Roles
AUGUST 2025
783Before Incident
Breach
01 Aug 2025Dynatrace
Dynatrace

Dynatrace Customer Data Exposure via Salesloft’s Drift Application Breach

730After Incident
MEDIUM-53
DYN3932439090925
In August 2025, Dynatrace experienced a third-party breach via Salesloft’s Drift application, which exploited integrations with Salesforce CRM, granting unauthorized access to partial customer data. The exposed information was limited to basic business contact details (e.g., names of customer representatives and company identifiers) stored in Salesforce systems used for business operations. No sensitive customer usage data, Dynatrace products, services, or operational systems (including monitoring/observability) were compromised. The company disabled the Drift integration, launched an investigation with external cybersecurity experts, and confirmed no evidence of broader exposure. While no direct financial or reputational harm was reported, Dynatrace warned customers of potential phishing or social engineering risks leveraging the leaked contact details. Salesloft and Salesforce restored secure connections by September 7, 2025, and Dynatrace continues monitoring for suspicious activity.
INCIDENT DETAILS -
TYPE
data breachthird-party compromiseunauthorized access
IMPACT
basic business contact details (names, company identifiers)Salesforce CRM (limited to Drift integration)Operational Impact: None (Dynatrace operations remained uninterrupted)Brand Reputation Impact: Potential risk due to exposure of customer contact dataIdentity Theft Risk: Low (only basic contact details exposed)
DATA BREACH
business contact details (names, company identifiers)Sensitivity Of Data: Low (no sensitive customer usage data, support cases, or authentication details)Names of customer representativesCompany identifiers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Dynatrace ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Dynatrace's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Dynatrace's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Dynatrace ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Dynatrace's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?