Threat actors use custom AuraInspector to harvest data from Salesforce systems
ID: f5d6ce72-e365-5523-aa16-e48baabe8243
STIX ID: report--f5d6ce72-e365-5523-aa16-e48baabe8243
Feed Name: Security Affairs
Threat Score
Attackers are mass-scanning public Salesforce Experience Cloud sites using a modified AuraInspector tool to exploit overly permissive guest user settings and extract CRM data (e.g., Accounts, Contacts, Leads). Salesforce characterizes this as exploitation of customer misconfigurations (not a platform vulnerability), attributes activity to a likely threat actor (possibly ShinyHunters), and recommends securing guest user settings, disabling unnecessary APIs, and monitoring logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
