Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.

The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.

In 

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps

Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps Source: Hacker News

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an