惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
O
OpenAI News
WordPress大学
WordPress大学
P
Proofpoint News Feed
J
Java Code Geeks
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Register - Security
The Register - Security
Engineering at Meta
Engineering at Meta
H
Help Net Security
人人都是产品经理
人人都是产品经理
Vercel News
Vercel News
N
Netflix TechBlog - Medium
F
Full Disclosure
U
Unit 42
Latest news
Latest news
N
News and Events Feed by Topic
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
I
InfoQ
L
LINUX DO - 最新话题
T
Threat Research - Cisco Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
K
Kaspersky official blog
Google Online Security Blog
Google Online Security Blog
小众软件
小众软件
I
Intezer
V
V2EX
S
SegmentFault 最新的问题
C
CERT Recently Published Vulnerability Notes
阮一峰的网络日志
阮一峰的网络日志
Security Archives - TechRepublic
Security Archives - TechRepublic
Recent Announcements
Recent Announcements
C
Check Point Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Recorded Future
Recorded Future
博客园 - Franky
Project Zero
Project Zero
S
Securelist
Attack and Defense Labs
Attack and Defense Labs
Spread Privacy
Spread Privacy
The Hacker News
The Hacker News
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
NISL@THU
NISL@THU
云风的 BLOG
云风的 BLOG
S
Secure Thoughts
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Salesforce

How We Protect Our Data as Customer Zero Scale Your MRR: Subscription Management For Small Business Streamlining Commerce Media Ad Inventory Management 12 AI Sales Strategies for Startups That Actually Work Sell Smarter: Ecommerce Metrics To Track For Your Small Business Shop Apply the Orchestration Density Framework to Your Next Automation Decision Wait, Black Friday Planning In Spring? It’s Time to Start Holiday Promotions AI-First Operations, One Process at a Time How BCU Is Transforming Banking Service with Agentforce Salesforce Headless 360: What the Agent Consumer Means for Your Integration Architecture Meet Customers Where They Are: Agentforce Contact Center Now Offers WhatsApp Voice 11 Free Lead Generation Tips for Small and Growing Businesses SFR-VibeTrain: The Agent That Trains Agents Why Technical Accuracy is the Wrong Metric for Agent Success Join Us in the Community Hub at Connections 2026 The Best Way To Build AI Agents That Customers Trust 5 Ways AI is Changing the Communication Game For Startups Trust in the Era of Agents: Highlights from the 2nd Annual Trusted AI Impact Report You Can Be an Agentic Enterprise No Matter What Size Business How to Make Your Email Marketing Accessible for Everyone What is Headless? Don’t Lose Your Head, SMBs: It’s a Good Thing Architect the Future UI: Slack as Your Agentic Surface Point of Sale Innovations to Modernize the Shopper Experience Governing the Agentic Enterprise at Scale with MuleSoft Omni Gateway How to Cut Service Time with Case Routing Automation 5 Tips for Marketers to Get Started with Salesforce Flow No One is Vibe Coding Trade Promotion Management 7th Edition State of Sales Report: 3 Growth Trends for Startups and SMBs How the Architect Vista Brought Architectural Thinking to Life at TDX 2026 5 Steps to Develop an Architect Mindset With AI Why AI Isn’t Replacing Developers, It’s Empowering Them 10 Ways to Make Your AI Agent a Better Communicator AI in Design 2025: What Real Use Taught Us. How Salesforce Personalization Learns Which Offers Drive Revenue The 4-Step Guide to Salesforce Agent and Application Development Get Ready for Connections 2026: Top Sessions and New Reveals 8 Ways AI Agents Are Evolving in 2026 4 Principles to Make the Right Salesforce UI Decisions Apprentice Journey Shines a Light on Talent Pathways at Salesforce Agent Script: The Control Plane for Agentic Decisions Scaling the Agentforce Life Sciences Ecosystem to Drive the Future of Pharma and MedTech Unlocking Unstructured Data: Building AI-Powered Support Triage with Data 360 Asking For a Friend: What Are Rich Communication Services (RCS)? 5 Slack Shortcuts For Small Teams 195% ROI In Field Service? Here’s How They Did It Submit Your Architect Session: The Dreamforce 2026 Call for Participation Is Open What Is an AI Assistant for Small Business? B2C Commerce April release: Transforming the B2C developer experience with agents Meet Your 24/7 Prospecting Partner — And 5 More Stand-Out Features In Our April Release 11+ Small Business YouTube Channels You Need to Follow Today Stop Treating Disputes Management Like IT Tickets Limitless Service: A New Operating Model for Growth in the Agentic Era What is Transactional Reconciliation in Email and SMS Marketing? How to Prepare for National Small Business Week (2026) How to Design a High-Scale Multi-Cloud Incident Journey 10 Ways An AI CRM Can Amplify Your Startup Vibe Code Better Agents with Agentforce Free vs. Paid CRM: Which is Right for Your Business? Salesforce Customer Success Awards 2026: Lead Era of the Agentic Enterprise 12 Free Webinars for Small Business Owners (2026) The Agentforce Life Sciences Consultant Certification Maximize Growth: The Power of Partnerships for SMBs Salesforce AI Research at ICLR 2026 Data Protection For Small Business: How To Safeguard Yourself Beyond 100K Tokens: Evaluating AI Agents in Long-Context Software Engineering Top 32 Small Business Tools To Try Today 6 New Innovations Redefining Salesforce Development How to Win the Battle for Attention in the Agentic Email Inbox Mastering the Eisenhower Matrix: Prioritize Like a Pro 10 Signs It’s Time To Upgrade Your CRM and How To Get Started (2026) Celebrating 10 Years of Financial Services Innovation How SMBs Can Gain An Edge With Agentic AI: Key Trends From Our Marketing Report How MAN Truck & Bus is Shaping the Future of Sales with Salesfive Introducing the Future of Salesforce Data Protection: Backup & Recover Next Stop Making AI Slop – Build a Foundation for Authentic AI Content 5 Tips to Help Marketers Navigate AI Email Summaries Data Sharing: Is it Safe? Is it Secure? Everything You Need to Know Small Business Week Readiness: 4 Things to Do Before May (2026) How Salesforce Employees Make an Impact During Earth Month AI Agents Are Advancing Rapidly… Is Your Testing Strategy Keeping Up? What Is Microproductivity and Why Is It Helping So Many Teams? TDX 2026 Roundup: Agentforce Edition 3 Ways Salesforce Connections Has Boosted My Career AI Agents Don’t Just Answer‌ — ‌They Act. Do You Have a Governance Strategy? The Future of MedTech Field Execution is Agentic 5 Steps to Prepare Your Data For an AI CRM From Break/Fix to Profit Engine: Aftermarket Service for Robot OEMs Building Trusted Human-Agent Collaboration: A Practical Framework ISV Strategy for the Salesforce Summer ’26 Release 5 Email Marketing Tips for Small Business Commerce Shops Should You Give Your AI Agent a Human Name? Creating Pathways into AI for People with Disabilities The Organized Chaos of Upfronts: 3 Hurdles Impacting Your Yield Trying to Scale Beyond ‘One-Off’ AI Tasks? You’re Probably Using the Wrong Interface What is Cost Per Lead (CPL)? The Case for Unified CCaaS and CRM — And Why the Data Makes It Clear In the New Era of AI, You Need to Win Over Both Humans and Agents What Is SPIN Selling? A Way to Build Trust With Your Customers G2 Crowns Salesforce as Best Financial Services Software Hidden Insights: The Guide to Tableau For Small Business Owners
Strengthening Salesforce Security Against AI-Driven Threats
Salesforce S · 2026-05-13 · via Salesforce

The rapid expansion of AI has changed the cybersecurity risk landscape for every organization. At Salesforce, Trust is our #1 value, and we’ve always built our platform to be secure by design and to enable our customers as security partners. As AI-driven threats evolve and grow more sophisticated, we continue to lead the industry by hardening our defenses and enhancing security protections. We’re making it easier than ever for customers to act as part of our shared security responsibility — with readily available controls, by meeting them in-app, and continuously making their security experience easier.

As part of these efforts we are proactively enforcing stronger customer security practices and configuration settings, expanding our portfolio of security products, and introducing new expert-guided services for customers. No matter where you are on your security journey, Salesforce is with you every step of the way.

Shifting Threat Landscape

The rise of AI has fundamentally altered the tools and tactics used by malicious actors. Today’s attackers are using AI to automate credential theft, generate convincing phishing campaigns at scale, and conduct reconnaissance across vast numbers of targets simultaneously. Attacks that once required a skilled team of hackers can now be executed by a single bad actor armed with an AI-powered toolkit. In an AI-driven threat landscape where vulnerabilities can be exploited at rapid speed, it’s critical that customers and providers continue to take their commitment to shared security responsibility seriously. 

To better protect our customers from these quickly evolving threats, Salesforce is hardening customer configured controls in the Salesforce Platform that protect against these attack vectors:

  • Account Takeover (ATO): AI-enhanced credential stuffing and phishing attacks can compromise user accounts — even those with complex passwords — by bypassing traditional login protections. Once inside, attackers can operate undetected for extended periods.
  • Data Exfiltration: Bulk report exports and large data queries are prime targets. Sophisticated actors are using AI to automate these requests, extracting data at speeds that outpace manual detection.
  • Identity-Based Social Engineering: AI is enabling attackers to craft highly personalized phishing and vishing (phishing via phone call) campaigns using data harvested from earlier breaches. Admins and privileged users are especially high-value targets, because their access is broad. 

These are the exact vectors our Cyber Security Operations Center (CSOC) team responds to every day — and the controls we’re enforcing are designed specifically to address them.

Ongoing Security Enhancements

Salesforce provides a secure platform by default, and we are committed to equipping our customers with the tools and visibility to evolve their security posture and stay ahead of this shifting landscape. That’s why beginning in June 2026, Salesforce is proactively enforcing stronger customer security practices and configuration settings across all customer orgs. Make sure to review the new Security-Related Product Updates article for official enforcement timelines. Below is a summary of what’s changing, and why it matters.

1. Multi-factor Authentication (MFA) for All Salesforce Users

MFA has been required for users since 2022. Beginning June 2026, MFA will be enforced for all user logins — direct UI and SSO — across both production and sandbox orgs. MFA adds a critical second layer of verification, and is the single most impactful control against account takeover.

2. Phishing-Resistant MFA for Admins and Privileged Users

Users with the System Administrator profile or permissions such as Modify All Data, View All Data, Customize Application, or Author Apex will be required to use Phishing Resistant MFA (PRMFA). Phishing-resistant methods are cryptographically bound to a specific site, making them resistant to adversary-in-the-middle phishing attacks. Though only privileged users are required to use PRMFA, we strongly encourage organizations to adopt this control for all users.

3. Step-up Authentication for Report Actions

A mandatory time-based step-up authentication framework will be implemented for report actions. Users are challenged after a configurable window (2–120 minutes, defaulting to 120) has elapsed since their last verification. Report exports are one of the most common vectors for data exfiltration. Verification at the point of data access — not just at login — ensures intent is confirmed even in a long-running session.

4. Step-up Authentication for Anomalous Report Behavior

Salesforce is making report actions more intelligent by implementing machine learning–based anomaly detection. When significant deviations from a user’s normal patterns are detected, the user is challenged with step-up MFA (an additional identity verification step) on their next report export or other sensitive action attempt before action is granted. 

5. Transaction Security Policy Enhancements (Shield and Event Monitoring Customers)

For customers with Salesforce Shield, we’re enhancing Transaction Security Policies (TSP) by upgrading passive monitoring into active prevention. A default TSP on ReportEvent will be triggered when a UI export exceeds 10,000 records, requiring step-up authentication, and a new Modify Transaction Security Policy permission will govern TSP management going forward, allowing the platform to intervene before data leaves the org.

6. Email Domain Verification

Email domain verification (already in enforcement) is required to send emails from Salesforce. With this change, emails will fail to send from Salesforce if the email domain isn’t verified via either an active DKIM key or a verified entry in the authorized email domain list. This is intended to help defend against AI-powered spoofing attacks.

7. Anonymizing Proxy Blocking

Salesforce blocks connections from anonymizing VPNs, proxies, and high-risk IPs, as well as through anomaly detection for login activity, helping to prevent unauthorized access to Salesforce. See the product change articles for the most up to date details and dates.

Quickly Scale Using Built-In Controls and Security Products

The platform-level enforcements outlined above are designed to significantly raise your security baseline. But those aren’t the only security controls available — customers also have access to built-in controls and add-on security products to assist them along the way.

Built-In Platform Controls

Every org includes powerful baseline tools available right now. One tool is Security Health Check, which is built into Setup and benchmarks your org against Salesforce’s baseline security standards. Health Check highlights potential misconfigurations that attackers may target, like weak password policies or overly long session settings, and surfaces a prioritized remediation list.

As of the Salesforce Spring ’26 release, the Security Health Check tool now features automated proactive notifications that alert admins to changes in their organization’s security score, making it easier than ever to have visibility into your org’s security controls.

Other strongly encouraged security controls include:

  • Login IP Restrictions: Limit authentication to trusted network locations, with an option to enforce IP validation on every request — not just at login.
  • Session-Level Policies: Configure the step-up authentication cadence for reports and dashboards directly from the Identity Verification page.

Salesforce’s Security Products

Salesforce also offers advanced controls to scale your security and customize your defense-in-depth strategy. These solutions are designed for customers who want enhanced levels of security, resilience, and compliance, like those managing sensitive data or operating in regulated industries.

Salesforce Shield 

Salesforce Shield offers a level of protection, visibility, and control that goes beyond the native platform baseline. With this powerful suite of data security products, you can monitor, encrypt, identify and classify with ease, safeguarding your critical and sensitive data. Shield consists of four products:

  • Event Monitoring provides comprehensive audit logs of more than 90 events including logins, data exports, and API calls. Transaction Security Policies (TSPs) let you define fully customizable, Flow-driven rules for blocking, alerting, or requiring step-up authentication on any monitored event. With the new default TSP for ReportEvent, Shield customers gain active exfiltration prevention from day one.
  • Field Audit Trail allows you to track changes for up to 60 fields per object and retain that data for forensic investigations and compliance audits indefinitely or customized to your needs.
  • Platform Encryption protects data at rest at the field level using customer-managed keys.
  • Data Detect helps you automate sensitive data discovery (like PII or credit card numbers) across your org. This allows you to quickly identify which fields may need to be classified or encrypted without manual scanning.

Security Center 

For customers managing one or more Salesforce orgs, Security Center aggregates security health data across every connected org into a single dashboard — surfacing configuration drift, compliance gaps, and threat detection signals without context-switching. 

Data Mask & Seed 

In both testing and production environments, data masking can help obscure personal or information. Data Mask & Seed allows you to provide realistic data for admins and developers while protecting sensitive customer information from leaks and unauthorized access. 

NEW: In-App Security Health Review for Signature Success Plan Customers

Another step we’re taking to help our customers identify and optimize their platform security is with the Security Health Review, a new expert-guided service currently available to Signature Success Plan customers. You can quickly evaluate 400+ security controls across your org by going to Setup directly in Salesforce and searching for “Security Health Review.” There’s also an Agent to assist with any questions along the way. From there, your Customer Success Manager (CSM) will partner with you to build a remediation plan to address all findings.

Unlike one-time competitor assessments, the Security Health Review isn’t a snapshot — we stay with you continuously along your journey, evolving recommendations as your org and the threat landscape change. For Signature customers preparing for the June 2026 enforcement wave, this is the most comprehensive readiness check available.

Our Commitment to Trust

Salesforce’s 2026 security enforcement reflects our ongoing commitment to helping our customers stay ahead of the threat landscape. We’re meeting you where you are — in-app, in the platform, and now through expert-guided services — to make acting on shared security responsibility as straightforward as possible.

For the latest guidance, advisories, and resources, visit security.salesforce.com.

Take Action: Prepare for the Upcoming Changes

Join one of our upcoming webinars to learn more about the new Salesforce Platform security enhancements:

Join an upcoming Security in Action virtual workshop

Learn how to proactively protect your org, and stay current on security tools