Topic: misconfiguration exploitation
-
ShinyHunters Hackers Launch Massive Salesforce Attack
Salesforce is urging customers to immediately review security settings due to a widespread data theft campaign by the ShinyHunters group, which exploits misconfigured guest user permissions on public-facing sites. The attackers use a customized tool to scan for and extract exposed data, which is ...
Read More » -
ShinyHunters Claims New Salesforce Data Theft Attacks
Cybercriminals, notably the ShinyHunters group, are exploiting misconfigured guest user permissions in Salesforce's Experience Cloud to access sensitive data, though Salesforce attributes this to customer security settings, not a platform vulnerability. Salesforce advises administrators to immedi...
Read More » -
ShutterGap: 3.7M AWS Resources Exposed Outside CSPM/CNAPP View
Over 3.7 million short-lived AWS resources with sensitive data are publicly exposed each year, often lasting only minutes or hours,too brief for traditional cloud security tools (CSPM and CNAPP) to detect but long enough for attackers to exploit. This security gap is worsening due to AI-driven at...
Read More »