Salesforce infrastructure abuse: Stopping email scams and spam sent via SFDC · Blog · Sublime Security
ID: 8ec0e9cd-5a96-5f9d-aa75-54e498a84537
STIX ID: report--8ec0e9cd-5a96-5f9d-aa75-54e498a84537
Feed Name: Sublime Security Blog
Sublime's Attack Spotlight details multiple, active email campaigns that leverage legitimate Salesforce infrastructure to conduct spam, credential- and callback-phishing, and crypto wallet theft (including impersonation, redirect chains through Salesforce and free hosting like Cloudflare pages, and phishy CTAs). The report presents example messages, recurring signals (infrastructure abuse, redirects to free pages, brand impersonation, urgency, generic greetings), and the detection signals and AI-driven mitigations used to block these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
