惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
S
Security @ Cisco Blogs
N
News and Events Feed by Topic
H
Hacker News: Front Page
Attack and Defense Labs
Attack and Defense Labs
S
Secure Thoughts
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
T
Threat Research - Cisco Blogs
Google Online Security Blog
Google Online Security Blog
Spread Privacy
Spread Privacy
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
T
Tenable Blog
博客园 - 叶小钗
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
量子位
P
Proofpoint News Feed
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
宝玉的分享
宝玉的分享
Recorded Future
Recorded Future
The Register - Security
The Register - Security
F
Fortinet All Blogs
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
S
Schneier on Security
V
Vulnerabilities – Threatpost
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
GRAHAM CLULEY
G
Google Developers Blog
月光博客
月光博客
V
V2EX
T
Troy Hunt's Blog
A
Arctic Wolf

The Register - Off-Prem: SaaS

Snowflake to burn $6B on AWS Graviton CPUs and AI accelerators Google Cloud suspended major customer Railway.com without cause, causing outage Anthropic comes for the midmarket software spend ServiceNow under siege as Atlassian adds to ITSM take-outs Survey: US workers are not keen on Microsoft's AI Service change takes down Microsoft Outlook for iOS Workday, Rippling, Slack lflunk data access test: Fivetran UK tribunal sends £2B claim accusing Microsoft of overcharging for licensing to trial The spaghettified DBMS chart that shows Oracle's crown is slowly slipping Atlassian’s new data collection policy protects rich customers while AI eats the rest Atlassian to train AI on user data unless law or cash say no McGraw Hill linked to 13.5M-record data leak UK told its Big Tech habit is now a national security risk How ServiceNow gets customers to gorge at the AI trough Salesforce is taking on ServiceNow in ITSM. The winner is AI Salesforce is taking on ServiceNow in ITSM. The winner is AI Snowflake manager on 'Spider-Man' theory of AI agents Minnesota payroll problems grew after Workday, say auditors Salesforce looks to Slackbot to help solve SaaSpocalypse ServiceNow salesman sues employer in commission dispute ServiceNow salesman sues employer in commission dispute Big Tech has not enforced Australia’s social media ban 'Emphathetic 'Salesforce bots to help fired via Labor Dept Datadog bets DIY AI will mean it dodges the SaaSpocalypse Snowflake's ongoing pitch: bring AI to data, not vice versa CMA dithers as Microsoft's cloud meter runs on your dime Salesforce acquihires team behind Clockwise for Agentforce CMA cracks knuckles, eyes Adobe's cancellation fees SAP's grand cloud escape plan €2B short of the runway Microsoft 365 pauses Copilot creep after admins cry foul Salesforce buyback to saddle company with debt until 2066 India tests whether AI can stop trains hitting elephants Adobe CEO Shantanu Narayen to step down after 18 years Adobe CEO Shantanu Narayen to step down after 18 years Pentagon praises Palantir tech for battlefield strike speed Atlassian to shed ten percent of staff, because AI Atlassian's new Jira migration tool slowed down cloudy moves Oracle says AI coding is helping it dodge SaaSpocalypse Vendors building tools to clean up messes made by AI agents Iran is the first out-loud cyberwar the US has fought Microsoft postpones new Outlook migration to 2027 Okta CEO ‘paranoid’ as vibe coders stir SaaS-pocalypse fears Capita £370M Whitehall outsourcing deal challenged in court Claude having artificially intelligent hiccups and access lockouts for over two hours Claude outage hits chat, API, vibe coding SaaS-pocalypse isn't coming any time soon SaaS-pocalypse isn't coming any time soon Half of German-speaking SAP users to stay on ECC to 2030 Half of German-speaking SAP users to stay on ECC to 2030 Salesforce CEO declared victory over flagging software sales Workday CEO's AI talk can't shake off weaker sales forecast Microsoft teases ‘reimagined SharePoint’ with added AI Palantir spent $25M on CEO flights for chatty Karp Microsoft throws spox under the bus in ICC email flap ServiceNow buys Pyramid Analytics ServiceNow buys Pyramid Analytics Supply chain breaches fuel cybercrime cycle, report says Apple inserts ads for its premium productivity services Apple inserts ads for its premium productivity services Workday CEO steps down amid layoffs and market jitters Workday CEO steps down amid layoffs and market jitters Counting the waves of tech industry BS from blockchain to AI Atlassian swears it can deliver AI without blowing out costs Workday layoffs to hit about 400 jobs Rise of AI means companies could pass on SaaS Estonia tests Euro alternatives amid Microsoft rollout MEP: 'The EU runs on Microsoft', Uncle Sam could turn it off Azure outages ripple across multiple dependent services Europe shrugs off tariffs, plots to end tech reliance on US Microsoft ends some standalone SharePoint and OneDrive plans TikTok’s US joint venture off to a rocky start Oracle, Michael Dell, invest in JV to run TikTok USA Data storage cloud Snowflake buys ITOM platform Observe ServiceNow snags Microsoft vet to run legal amid M&A spree ServiceNow to buy Armis in $7.7 billion security deal ServiceNow unworried by Salesforce targeting its ITSM core ServiceNow mulls Armis buy to gain IT visibility Workday project at Washington University hits $266M Here we go again: Microsoft in UK court over cloud licensing
Mandiant plugs Salesforce leaks with open source tool
Connor Jones Connor Jones · 2026-01-13 · via The Register - Off-Prem: SaaS

SaaS

Mandiant open sources tool to prevent leaky Salesforce misconfigs

AuraInspector automates the most common abuses and generates fixes for customers

Mandiant has released an open source tool to help Salesforce admins detect misconfigurations that could expose sensitive data.

Launched on Monday, AuraInspector targets access control issues in Salesforce Aura, the UI framework for Experience Cloud sites. While Aura components aren't inherently insecure, their complexity often leads to dangerous misconfigurations.

An example? If unauthenticated users gain access to all records in a Salesforce Account object, attackers can exploit the getItems method to steal data.

"This is a common misconfiguration encountered during real-world engagements," Mandiant said in its announcement.

Though typically limited to 2,000-records per request, attackers can bypass this by changing sort orders. It's an inconsistent method, and one that may yield duplicate records for attackers.

Another way to bypass this limit is to abuse the functionality of the GraphQL API, which is made available by default to all guest accounts.

Salesforce maintains the API isn't a vulnerability if object access is properly configured, but misconfigurations can expose broad swaths of sensitive information.

Mandiant said AuraInspector can also help prevent attackers from gaining access to Record Lists and admin panels via Home URLs, while also supporting other use cases.

The tool, available now for free, automates potential abuse techniques and recommended remediation strategies to help defenders identify damaging misconfigurations.

Mandiant says all of AuraInspector's operations are read-only and the tool will not make any modifications to Salesforce instances on its own.

Despite many customers switching to Lightning Web Components for new sites, Aura is still widely used for legacy functionality, and security companies continue to issue alerts about the dangers of Aura misconfigurations.

Varonis, for example, warned in July it is trivial to locate Salesforce Experience Cloud sites, and its own researchers were able to retrieve "troves of exposed sensitive records" by abusing Aura methods.

Infosec blogger Brian Krebs also drew attention to widespread issues with Salesforce Community sites in 2023 after discovering that banks and healthcare providers were leaking sensitive data through similar means. ®