惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
U
Unit 42
MyScale Blog
MyScale Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
量子位
IT之家
IT之家
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
Recent Announcements
Recent Announcements
V
Visual Studio Blog
G
Google Developers Blog
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园 - 聂微东
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
博客园 - 司徒正美
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
ShinyHunters Targets Hundreds of Websites in New Salesfor...
2026-03-10 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

Salesforce has urged Experience Cloud customers to audit their website configurations after reports that a notorious threat group has already stolen data from hundreds of companies.

The SaaS giant said that it had been tracking an increase in threat actor activity targeting misconfigurations of publicly accessible sites built using its Experience Cloud platform.

“Specifically, we have identified a campaign in which malicious actors are exploiting customers’ overly permissive Experience Cloud guest user configurations to potentially access more data than targeted organizations intended,” it explained.

The group has been using a customized version of an open source tool originally developed by Mandiant (Aura Inspector) to perform mass scanning of the /s/sfsites/aura API endpoint. The tool apparently identifies vulnerable CRM objects and extracts data from misconfigured endpoints, Salesforce said.

“Data harvested in these scans, such as names and phone numbers, is often used to build follow-on targeted social engineering and vishing (voice phishing) campaigns,” it continued.

Read more on ShinyHunters campaigns: New Data Theft Campaign Targets Salesforce via Salesloft App.

Salesforce was at pains to point out that the threat actors are exploiting a “customer-configured guest user setting, not a platform security flaw.”

ShinyHunters Gives a Final Warning

The infamous ShinyHunters group has claimed responsibility for the campaign. In screenshots from its leak site published on X (formerly Twitter) it claimed to have breached “several hundreds” of companies.

It claims to have compromised around 400 websites and 100 “high-profile companies."

That would suggest that it did indeed use the contact details cited by Salesforce and obtained via the website intrusions in order to perform follow-on social engineering, network intrusions and wider data theft.

Salesforce Urges Immediate Action

Salesforce claimed that any Experience Cloud customers that are using the guest user profile and have configured permissions “to allow public access to objects and fields not intended to be publicly available” could be affected.

It urged these customers to:

  • Audit guest user permissions and enforce a least privilege access model to ensure these profiles are restricted to the “absolute minimum” objects and fields needed for the site to function
  • Ensure the Default External Access for all objects is set to “private”
  • Uncheck “Allow guest users to access public APIs” in site settings and uncheck “API Enabled” in the guest user profile’s System Permissions
  • Uncheck “Portal User Visibility” and “Site User Visibility” in Sharing Settings to stop guest users from enumerating internal organization members
  • If the site does not require unauthenticated visitors to create their own accounts, disable self-registration
  • Review Aura Event Monitoring logs for unusual access patterns 

​ShinyHunters has a long track record of going after Salesforce customers, having targeted their instances on multiple occasions in connected campaigns last year.