Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Tanium

Tanium Vendor Cyber Rating & Cyber Score

tanium.com

Tanium is the Autonomous IT company. Driven by AI and real-time endpoint intelligence, Tanium Autonomous IT empowers IT and security teams to make their organizations unstoppable. Many of the world’s leading organizations trust Tanium’s single, unified platform for endpoint management and security to innovate faster, stay resilient and move business forward with confidence, at scale. Autonomous IT. Unstoppable Business. To learn how Tanium delivers Autonomous IT for unstoppable business - visit www.tanium.com and follow us on LinkedIn and X.


Tanium A.I CyberSecurity Scoring

Tanium
Company Information
Website:http://www.tanium.com
Employees number:2,293
Number of followers:88,082
NAICS:541514
Industry Type:Computer and Network Security
Homepage:tanium.com
Tanium Risk Score (AI oriented)
Between 600 and 649
logo
TaniumComputer and Network Security
Updated:
15/07/2026
637/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Tanium Global Score (TPRM)
xxxx
logo
TaniumComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Tanium
TaniumPoor
Current Score
637Caa (POOR)
01000
3 incidents
-44.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
685Before Incident
JUNE 2026
663Before Incident
Cyber Attack
22 Jun 2026Tanium
iRhythm Technologies, Jamf, ShapedPlugin, Tanium, Fortinet, Microsoft and Texas Parks and Wildlife Department: 22nd June – Threat Intelligence Report

Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22)

635After Incident
CRITICAL-28
FORSHATANMICJAMIRHTEX1782147825
Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22) This week’s cybersecurity landscape saw significant breaches, supply chain attacks, and emerging AI-driven threats, alongside critical vulnerabilities under active exploitation. ### Major Breaches & Attacks - Texas Parks and Wildlife Department suffered a third-party breach via its license system vendor, exposing driver’s license details, passport numbers, emails, phone numbers, and addresses of 3.1 million hunting and fishing license customers. Social Security numbers and payment data remained unaffected. - ShapedPlugin, a WordPress plugin vendor, fell victim to a supply chain attack, delivering malicious updates for three paid plugins. The malware installed a hidden fake WooCommerce plugin to steal admin credentials, database access, and 2FA details, while modifying affected sites. The compromise stemmed from the vendor’s release infrastructure. - iRhythm Technologies, a U.S. digital health firm specializing in remote cardiac monitoring, confirmed a cyberattack where threat actors via a social engineering breach of third-party business applications stole protected health information, proprietary data, and personal records. Clinical systems were not impacted. - Klue, a market intelligence platform, disclosed a breach after attackers used compromised legacy integration credentials to steal OAuth tokens linked to customer Salesforce environments. The tokens enabled the theft of sales and customer data from clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group claimed responsibility. ### AI-Driven Threats - Microsoft researchers uncovered AutoJack, an exploit chain where malicious web pages turn AI browsing agents into remote code execution vectors by abusing localhost trust, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket interface. - SearchLeak, a prompt injection technique in Microsoft 365 Copilot Search, was revealed to exfiltrate data including emails, authentication codes, and OneDrive/SharePoint files via crafted links abusing Bing image fetches. Microsoft patched the flaw as CVE-2026-42824. - Researchers analyzed OpenClaw AI agent flaws, demonstrating how hidden contacts and phishing emails could trigger prompt injections, code execution, and data leaks, exposing local tools, secrets, and enterprise data through trusted external interactions. ### Critical Vulnerabilities & Exploits - Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being exploited via unauthenticated API requests, enabling path traversal and root-level command execution, risking sandbox takeover and disruption of malware analysis and security workflows. - Microsoft confirmed CVE-2026-50656, a Defender zero-day allowing privilege escalation to SYSTEM via a race condition. A public proof-of-concept works on fully updated Windows 10 and 11, with a patch in development. - Cisco acknowledged active exploitation of CVE-2026-20262, an arbitrary file write flaw in Catalyst SD-WAN Manager. Authenticated attackers can overwrite system files and escalate to root, prompting patches for affected devices. - Splunk Enterprise’s CVE-2026-20253 is under active exploitation, allowing unauthenticated attackers to trigger file operations, potentially leading to remote code execution. Splunk confirmed limited attacks and released security updates. ### Threat Intelligence Highlights - A crypto clipboard hijacker, written in Rust and targeting Windows and macOS, was distributed via phishing sites and amplified on GitHub, SourceForge, YouTube, and legitimate news platforms. The malware swaps copied wallet addresses to redirect funds to attacker-controlled wallets.
INCIDENT DETAILS -
TYPE
Data BreachSupply Chain AttackCyberattackAI-Driven ThreatVulnerability Exploitation
MOTIVATION
Data TheftExtortionFinancial GainCredential HarvestingRemote Code Execution
IMPACT
Driver’s license detailsPassport numbersEmailsPhone numbersAddressesProtected health informationProprietary dataPersonal recordsSales dataCustomer dataOAuth tokensAdmin credentialsDatabase access2FA detailsWallet addressesLicense system vendorWordPress pluginsThird-party business applicationsSalesforce environmentsFortinet FortiSandboxMicrosoft DefenderCisco Catalyst SD-WAN ManagerSplunk EnterpriseDisruption of malware analysis and security workflowsSandbox takeoverPrivilege escalationFile operations leading to RCEYesYesNo
DATA BREACH
Driver’s license detailsPassport numbersEmailsPhone numbersAddressesProtected health informationProprietary dataPersonal recordsSales dataCustomer dataOAuth tokensAdmin credentialsDatabase access2FA detailsNumber Of Records Exposed: 3.1 millionHighYesYes
MAY 2026
662Before Incident
APRIL 2026
660Before Incident
MARCH 2026
658Before Incident
FEBRUARY 2026
656Before Incident
JANUARY 2026
654Before Incident
DECEMBER 2025
652Before Incident
NOVEMBER 2025
649Before Incident
OCTOBER 2025
708Before Incident
Breach
21 Oct 2025Tanium
Salesloft

Salesloft-Drift OAuth Token Breach

647After Incident
CRITICAL-61
DRI1593115102125
The Salesloft-Drift OAuth incident involved attackers stealing OAuth tokens from Salesloft’s development platform, exploiting them to access customer data across integrated applications like Salesforce and Google Workspace. The breach, executed by the threat group UNC6395, leveraged voice phishing (vishing) to trick administrators into authorizing malicious apps, bypassing multi-factor authentication (MFA). Over 700 organizations were impacted as the compromised tokens enabled attackers to exfiltrate sensitive customer information, leading to widespread revocation of Drift integrations. The incident exposed systemic risks in SaaS supply chains, where trusted third-party integrations became attack vectors, enabling potential data theft, cloud credential abuse, outages, or ransomware. Beyond immediate data exposure, the breach triggered forensic investigations, regulatory fines, lawsuits, reputational damage, and operational disruptions, highlighting the cascading risks of N-th degree vendor dependencies in modern cybersecurity ecosystems.
INCIDENT DETAILS -
TYPE
Data BreachCredential TheftSupply Chain Attack
MOTIVATION
Data ExfiltrationCredential HarvestingPotential Financial Gain (e.g., Dark Web Data Sales)
IMPACT
Customer DataCloud Credentials (AWS, Snowflake)Salesforce/Google Workspace DataSalesforceGoogle WorkspaceDrift IntegrationsConnected SaaS PlatformsTemporary Disabling of Drift IntegrationsCredential RevocationsForensic InvestigationsLoss of Trust in SaaS IntegrationsReputational Harm for Salesloft/DriftPotential LawsuitsRegulatory ScrutinyHigh (Stolen Cloud Credentials)PII Exposure via Connected Apps
DATA BREACH
Customer DataCloud Credentials (AWS, Snowflake)PII (via Connected Apps)Sensitivity Of Data: High (Credentials, PII, Business Data)
SEPTEMBER 2025
708Before Incident
AUGUST 2025
707Before Incident
JUNE 2025
762Before Incident
Breach
12 Jun 2025Tanium
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential

Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential

704After Incident
CRITICAL-58
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations. ### What Happened? On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress. Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed. ### How the Attack Unfolded The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain. ### Key Victims & Impact While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span: - Password management (LastPass) - Privileged access (BeyondTrust) - Endpoint security (Tanium, Jamf) - Threat intelligence (Recorded Future) - Bug bounty coordination (HackerOne) - Application security (Snyk) Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure. ### Broader Context: A Year of Supply Chain Attacks The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses. ### Regulatory & Industry Reactions - Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene. - Security vendors on the victim list face heightened procurement questions from enterprise buyers. - Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications. ### Lessons from the Breach The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires: - Automated expiration for pilot credentials. - Minimum-scoped OAuth grants (avoiding broad CRM access). - Recurring token audits to identify stale integrations. As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Business contact and CRM dataSystems Affected: Salesforce environmentsBrand Reputation Impact: Heightened procurement scrutiny for security vendors
DATA BREACH
Type Of Data Compromised: Business contact and CRM dataSensitivity Of Data: Low (non-core product data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Tanium ?
?
What was Tanium's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Tanium's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Tanium's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Tanium's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Tanium's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Tanium's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Tanium's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Tanium ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Tanium's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Tanium Cyber Scoring History | Rankiteo