Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool
ID: ee01fc28-71c8-5292-8bc0-9170d83a76ab
STIX ID: report--ee01fc28-71c8-5292-8bc0-9170d83a76ab
Feed Name: The Hacker News
Salesforce has alerted customers that a threat actor is using a customized version of the open-source AuraInspector tool to mass-scan publicly accessible Experience Cloud sites and extract data by exploiting overly permissive guest user configurations; this activity targets misconfigured guest profiles (not a core platform vulnerability) and has been linked by Salesforce to a known actor with tactics similar to prior attacks, with guidance to tighten guest access, disable guest API access, and monitor logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
