
The threat actor group ShinyHunters (also tracked as UNC6040/UNC6240) has claimed responsibility for a new wave of data theft attacks targeting Salesforce Experience Cloud (formerly Community Cloud) sites using the Aura framework.
Key Details of the Attack
The attackers are reportedly exploiting misconfigured guest user permissions on public-facing Salesforce sites. By leveraging these misconfigurations, they can exfiltrate sensitive data without needing valid credentials or bypassing MFA.
/s/sfsites/ endpoint).sortBy parameter.Salesforce and Expert Response
Salesforce has issued a security advisory clarifying that these incidents are not due to a vulnerability in the Salesforce platform itself. Instead, the breaches result from incorrectly configured guest user access.
Recommended Actions for Organizations:
#cloud #data #experience #exploits #for #heist #massive #news #salesforce #shinyhunters — News
© Bulletproof Servers. All rights reserved.