Salesforce confirms ShinyHunters exploited Experience Cloud sites

robot
Abstract generation in progress

Salesforce has confirmed that the ShinyHunters cybercrime group exploited misconfigured Experience Cloud sites, not a platform vulnerability. This incident affected hundreds of organizations due to overly broad guest user permissions. Attackers used a weaponized Aura Inspector tool to scan for and exploit these misconfigurations, prompting Salesforce to urge customers to audit permissions and disable public API access for guest users.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin