logo

Threat actors use custom AuraInspector to harvest data from Salesforce systems

ID: f5d6ce72-e365-5523-aa16-e48baabe8243

STIX ID: report--f5d6ce72-e365-5523-aa16-e48baabe8243

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Attackers are mass-scanning public Salesforce Experience Cloud sites using a modified AuraInspector tool to exploit overly permissive guest user settings and extract CRM data (e.g., Accounts, Contacts, Leads). Salesforce characterizes this as exploitation of customer misconfigurations (not a platform vulnerability), attributes activity to a likely threat actor (possibly ShinyHunters), and recommends securing guest user settings, disabling unnecessary APIs, and monitoring logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.