#salesforce-security

[ follow ]
Information security
fromSecuritymagazine
5 days ago

Why Are Platform Ecosystems - Like Salesforce - Often Targeted?

Salesforce warned users of increased threat actor activity exploiting misconfigured publicly accessible sites and permissive guest user settings to gain unauthorized data access for social engineering and vishing campaigns.
Information security
fromComputerWeekly.com
1 week ago

Salesforce tracks possible ShinyHunters campaign targeting its users | Computer Weekly

Salesforce Experience Cloud customers face attacks from ShinyHunters exploiting misconfigured guest user permissions, not product vulnerabilities, using a modified Aura Inspector tool to extract data.
Information security
fromSecurityWeek
1 week ago

Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign

ShinyHunters targets Salesforce instances through social engineering and misconfiguration exploitation, not platform vulnerabilities, prompting Salesforce warnings about overly permissive guest user settings.
Information security
fromThe Hacker News
1 week ago

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

Threat actors are exploiting misconfigured Salesforce Experience Cloud sites using a modified AuraInspector tool to extract sensitive data from overly permissive guest user profiles.
Information security
fromTheregister
1 week ago

ShinyHunters claims yet another Salesforce customers breach

ShinyHunters claims to have stolen data from approximately 100 high-profile companies including Salesforce, Snowflake, Okta, LastPass, Sony, and AMD through exploiting overly broad guest user permissions on Salesforce Experience Cloud sites.
Information security
fromTheregister
3 months ago

Salesforce flags another third-party security incident

Gainsight-published applications' compromised external connections allowed unauthorized access to some customers' Salesforce data; Salesforce revoked tokens and removed apps from AppExchange.
[ Load more ]