





























Salesforce has urged Experience Cloud customers to audit their website configurations after reports that a notorious threat group has already stolen data from hundreds of companies.
The SaaS giant said that it had been tracking an increase in threat actor activity targeting misconfigurations of publicly accessible sites built using its Experience Cloud platform.
“Specifically, we have identified a campaign in which malicious actors are exploiting customers’ overly permissive Experience Cloud guest user configurations to potentially access more data than targeted organizations intended,” it explained.
The group has been using a customized version of an open source tool originally developed by Mandiant (Aura Inspector) to perform mass scanning of the /s/sfsites/aura API endpoint. The tool apparently identifies vulnerable CRM objects and extracts data from misconfigured endpoints, Salesforce said.
“Data harvested in these scans, such as names and phone numbers, is often used to build follow-on targeted social engineering and vishing (voice phishing) campaigns,” it continued.
Read more on ShinyHunters campaigns: New Data Theft Campaign Targets Salesforce via Salesloft App.
Salesforce was at pains to point out that the threat actors are exploiting a “customer-configured guest user setting, not a platform security flaw.”
The infamous ShinyHunters group has claimed responsibility for the campaign. In screenshots from its leak site published on X (formerly Twitter) it claimed to have breached “several hundreds” of companies.
It claims to have compromised around 400 websites and 100 “high-profile companies."
That would suggest that it did indeed use the contact details cited by Salesforce and obtained via the website intrusions in order to perform follow-on social engineering, network intrusions and wider data theft.
Salesforce claimed that any Experience Cloud customers that are using the guest user profile and have configured permissions “to allow public access to objects and fields not intended to be publicly available” could be affected.
It urged these customers to:
ShinyHunters has a long track record of going after Salesforce customers, having targeted their instances on multiple occasions in connected campaigns last year.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。