Dynatrace A.I CyberSecurity Scoring
Dynatrace
Company Information
Website:https://www.dynatrace.com
Employees number:5,885
Number of followers:393,049
NAICS:5112
Industry Type:Software Development
Homepage:dynatrace.com
Dynatrace Risk Score (AI oriented)
Between 700 and 749
DynatraceSoftware Development
Updated:
31/08/2026
31/08/2026
704/1000
Moderate
Ba
Dynatrace Global Score (TPRM)
xxxx
DynatraceSoftware Development
Score locked

DynatraceModerate
Current Score
704Ba (MODERATE)
01000
3 incidents
-29.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
701
JULY 2026
696
JUNE 2026
692
MAY 2026
688
APRIL 2026
688
MARCH 2026
686
FEBRUARY 2026
684
JANUARY 2026
684
Vulnerability
14 Jan 2026 • Dynatrace
Node.js and Dynatrace: Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow
Node.js Critical Security Issue Leading to Denial-of-Service (DoS)
680
HIGH-4
NODDYN1768467414
Node.js Patches Critical DoS Vulnerability Affecting Widespread Ecosystem
Node.js has released urgent security updates to address a critical denial-of-service (DoS) vulnerability (CVE-2025-59466, CVSS 7.5) that could crash nearly all production Node.js applications if exploited. The flaw arises when stack space exhaustion occurs in user code while the `async_hooks` API is enabled, causing Node.js to exit abruptly with an error code (7) instead of throwing a catchable exception.
The issue stems from a bug in Node.js’s handling of stack overflows in conjunction with `async_hooks`, a low-level API used to track asynchronous operations. Frameworks and Application Performance Monitoring (APM) tools including React Server Components, Next.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry are affected due to their reliance on `AsyncLocalStorage`, a component built on `async_hooks`.
The vulnerability impacts all Node.js versions from 8.x (released in 2017) through 18.x, though only supported LTS and current releases have received patches. Fixed versions include:
- Node.js 20.20.0 (LTS)
- Node.js 22.22.0 (LTS)
- Node.js 24.13.0 (LTS)
- Node.js 25.3.0 (Current)
End-of-life (EoL) versions (8.x–18.x) remain unpatched. The fix rethrows stack overflow errors to user code rather than treating them as fatal, improving error handling predictability. Node.js acknowledged the fix as a mitigation, citing limitations in the ECMAScript specification and V8’s stance on stack exhaustion.
Alongside this flaw, Node.js patched three additional high-severity vulnerabilities (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465) enabling data leakage, symlink-based file reads, and remote DoS attacks. The updates underscore the need for prompt upgrades in affected environments.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2025
684
NOVEMBER 2025
682
OCTOBER 2025
680
SEPTEMBER 2025
732
Breach
25 Sep 2025 • Dynatrace
Salesloft
AI-Powered Supply Chain Attack via Compromised Salesloft-Drift Integration (2025)
677
CRITICAL-55
SAL2862828092525
The attack on Salesloft began with the compromise of an internal GitHub repository, where attackers stole a high-privilege OAuth token granting access to its Drift cloud application. Exploiting Drift’s trusted integrations, the attackers pivoted to Salesforce instances of multiple high-profile customers—including Palo Alto Networks, Cloudflare, Zscaler, and Tenable—exfiltrating customer conversation data, contact details, and sensitive business information. The breach exposed a supply-chain vulnerability, where a single compromised AI-powered integration (Drift’s chatbot) enabled mass data theft across 700+ organizations, including cybersecurity leaders. The attackers also harvested OpenAI API credentials, demonstrating the cascading risks of interconnected AI ecosystems. While companies like Okta mitigated damage via IP allow-listing, others faced reputational harm, forensic costs, and erosion of customer trust. The incident highlighted critical gaps in third-party risk management, token security, and AI integration monitoring, with long-term implications for enterprise security postures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
783
Breach
01 Aug 2025 • Dynatrace
Dynatrace
Dynatrace Customer Data Exposure via Salesloft’s Drift Application Breach
730
MEDIUM-53
DYN3932439090925
In August 2025, Dynatrace experienced a third-party breach via Salesloft’s Drift application, which exploited integrations with Salesforce CRM, granting unauthorized access to partial customer data. The exposed information was limited to basic business contact details (e.g., names of customer representatives and company identifiers) stored in Salesforce systems used for business operations. No sensitive customer usage data, Dynatrace products, services, or operational systems (including monitoring/observability) were compromised. The company disabled the Drift integration, launched an investigation with external cybersecurity experts, and confirmed no evidence of broader exposure. While no direct financial or reputational harm was reported, Dynatrace warned customers of potential phishing or social engineering risks leveraging the leaked contact details. Salesloft and Salesforce restored secure connections by September 7, 2025, and Dynatrace continues monitoring for suspicious activity.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Dynatrace ??
What was Dynatrace's A.I Rankiteo Cyber Score in July 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in June 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in May 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in April 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in March 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in February 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in January 2026 ??
What was Dynatrace's A.I Rankiteo Cyber Score in December 2025 ??
What was Dynatrace's A.I Rankiteo Cyber Score in November 2025 ??
What was Dynatrace's A.I Rankiteo Cyber Score in October 2025 ??
What was Dynatrace's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Dynatrace's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Dynatrace ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Dynatrace's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?