logo

'Overly Permissive' Salesforce Cloud Configs in the Crosshairs

ID: 33009c78-0469-5a90-aebf-9e5c9b005ba4

STIX ID: report--33009c78-0469-5a90-aebf-9e5c9b005ba4

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Salesforce reported that attackers are abusing misconfigured Experience Cloud guest user profiles—using a customized Aura Inspector to mass-scan public sites and directly extract CRM data—leading to multiple data theft and extortion campaigns attributed to financially motivated groups; Salesforce urges customers to audit guest user permissions, set defaults to private, disable unnecessary public APIs and self-registration, and monitor logs to mitigate further compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.