<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Salesforce Customers Hit by Third Major Attack Wave in Six Months

Salesforce warns of attacks exploiting guest settings, with ShinyHunters breaching 100 companies via Experience Cloud sites.
Content Team

Salesforce issued a security alert Saturday warning of ongoing attacks targeting customers' Experience Cloud sites. The threat group ShinyHunters claims to have breached about 100 companies by exploiting misconfigured guest user settings that allow unauthorized access to customer data.

Attackers are using a modified version of Mandiant's AuraInspector tool to scan public-facing sites and steal data from instances with overly permissive guest profiles. These settings are meant to give unauthenticated users access to public information, but excessive permissions let attackers view additional data without logging in.

This marks the third widespread attack spree against Salesforce customers since August, following incidents involving Gainsight and Salesloft Drift integrations.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo