'Overly Permissive' Salesforce Cloud Configs in the Crosshairs
ID: 33009c78-0469-5a90-aebf-9e5c9b005ba4
STIX ID: report--33009c78-0469-5a90-aebf-9e5c9b005ba4
Feed Name: Dark Reading
Threat Score
Salesforce reported that attackers are abusing misconfigured Experience Cloud guest user profiles—using a customized Aura Inspector to mass-scan public sites and directly extract CRM data—leading to multiple data theft and extortion campaigns attributed to financially motivated groups; Salesforce urges customers to audit guest user permissions, set defaults to private, disable unnecessary public APIs and self-registration, and monitor logs to mitigate further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
