logo

Salesforce issues new security alert tied to third customer attack spree in six months

ID: 38ededcc-6113-5845-9c05-55094ab80875

STIX ID: report--38ededcc-6113-5845-9c05-55094ab80875

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Salesforce reported active scans and data theft from publicly accessible Experience Cloud sites that have overly permissive guest user settings; a group linked to ShinyHunters claims responsibility and attackers used a modified AuraInspector to enumerate and query exposed CRM objects. Salesforce emphasizes this is caused by customer misconfigurations (not a platform vulnerability) and urges customers to restrict guest user permissions and apply least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.