BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Salesforce Warns of API Attacks Exploiting Cloud Misconfigs

Data stolen from misconfigured Salesforce sites using a customized open-source attack tool.

  • Threat actors are actively exploiting misconfigured Salesforce Experience Cloud sites to steal sensitive data.
  • The attackers are using a customized version of an open-source auditing tool called AuraInspector to scan and extract information.
  • Salesforce states this is not a platform vulnerability but a result of customers not implementing recommended security settings.
  • The campaign is part of a growing trend of identity-focused attacks used to fuel social engineering schemes.

Security teams are on high alert as Salesforce warned on March 10, 2026, of a surge in cyberattacks targeting improperly configured customer websites. This campaign exploits overly permissive guest user settings on publicly accessible Experience Cloud sites to access confidential data. Threat actors, possibly the known group ShinyHunters, are leveraging a modified version of the open-source AuraInspector tool for these scans.

- Advertisement -

The original tool, released by Google-owned Mandiant, was designed to identify misconfigurations. However, the actor’s customized version goes beyond identification to actively extract data from vulnerable endpoints. This activity focuses on sites where the guest user profile has not followed recommended configuration guidance.

Consequently, an unauthenticated attacker can directly query Salesforce CRM objects without logging in. Salesforce said it has “not identified any vulnerability inherent to the Salesforce platform associated with this activity.” The company emphasized that these attempts exploit customer configuration settings that increase exposure if not properly secured.

Meanwhile, the harvested data, such as names and phone numbers, is often repurposed for follow-on attacks. Salesforce noted this reflects a broader trend of identity-based targeting used for social engineering. The firm has urged customers to review guest user permissions and restrict API access immediately.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SpaceX may bar Robinhood, SoFi from IPO share sales – Reuters

SpaceX is reportedly considering excluding platforms like Robinhood (HOOD) and SoFi from its upcoming...

Nium Launches Stablecoin Card Platform via Visa, Mastercard

Nium has launched a platform enabling businesses to issue VISA and Mastercard cards funded...

BlackRock CEO Larry Fink’s 2026 Pay Hits $37.7 Million

BlackRock CEO Larry Fink's total compensation surged to $37.7 million for his role leading...

Bitcoin Dips to $65K, $400M Liquidated Amid Iran Tensions

Bitcoin fell to $65,112 over the weekend, liquidating over $400 million in trading positions.Donald...

Bitcoin rebounds to $67.4K as analysts eye $70K threshold

Bitcoin's 1.4% rebound to around $67,400 on Monday faces skepticism from analysts who warn...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading