logo

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

ID: ee01fc28-71c8-5292-8bc0-9170d83a76ab

STIX ID: report--ee01fc28-71c8-5292-8bc0-9170d83a76ab

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2026-03-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Salesforce has alerted customers that a threat actor is using a customized version of the open-source AuraInspector tool to mass-scan publicly accessible Experience Cloud sites and extract data by exploiting overly permissive guest user configurations; this activity targets misconfigured guest profiles (not a core platform vulnerability) and has been linked by Salesforce to a known actor with tactics similar to prior attacks, with guidance to tighten guest access, disable guest API access, and monitor logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.