Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
ID: 455cca0c-43ed-51bc-8072-e83ffa361667
STIX ID: report--455cca0c-43ed-51bc-8072-e83ffa361667
Feed Name: The Hacker News
Microsoft mapped a mid‑2025 to mid‑2026 set of Salesforce intrusions that abused OAuth trust—through vishing, stolen tokens from compromised third‑party integrations (notably Salesloft/Drift, Gainsight, and Klue), and misconfigured Experience Cloud guest access—to enumerate and exfiltrate CRM data and credentials across hundreds of organizations; the findings drove new detection and governance features from Microsoft and Salesforce to better monitor connected apps and OAuth activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
