Modified AuraInspector scans misconfigured Salesforce Experience Cloud sites, extracting CRM data and enabling targeted vishing campaigns.
And they abused a Mandiant-developed open source tool in the attacks ShinyHunters told The Register that it has stolen data from about 100 high-profile companies in its latest Salesforce customer data ...
Salesforce says no bugs being exploited, but the hackers claim otherwise.
Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give ...
Salesforce has issued another warning to customers as the notorious ShinyHunters cybercrime group has announced a new ...
Some customers have mishandled guest user configurations otherwise intended to allow third-party access to important — and sensitive — client data.
Salesforce customers are abandoning their sites without deactivating them, leaving sensitive corporate, vendor, and user data behind. The problem occurs within what the service calls "Communities," ...
Research highlights the risks posed by inactive Salesforce sites that continue to pull sensitive business data and can be easily exploited by malicious actors. Improperly deactivated and unmaintained ...