Topic: salesforce security

  • ShinyHunters Claims New Salesforce Data Theft Attacks

    ShinyHunters Claims New Salesforce Data Theft Attacks

    Cybercriminals, notably the ShinyHunters group, are exploiting misconfigured guest user permissions in Salesforce's Experience Cloud to access sensitive data, though Salesforce attributes this to customer security settings, not a platform vulnerability. Salesforce advises administrators to immedi...

    Read More »
  • ShinyHunters Hackers Launch Massive Salesforce Attack

    ShinyHunters Hackers Launch Massive Salesforce Attack

    Salesforce is urging customers to immediately review security settings due to a widespread data theft campaign by the ShinyHunters group, which exploits misconfigured guest user permissions on public-facing sites. The attackers use a customized tool to scan for and extract exposed data, which is ...

    Read More »
  • Salesforce Probes New Security Incident Similar to Salesloft Breach

    Salesforce Probes New Security Incident Similar to Salesloft Breach

    Salesforce is investigating a security incident involving unauthorized access to customer data through Gainsight app integrations, leading to revoked tokens and temporary removal of the apps from AppExchange. Threat actors linked to ShinyHunters compromised Gainsight OAuth tokens to access Salesf...

    Read More »
  • Salesforce Blames Social Engineering for Ransomware Breaches

    Salesforce Blames Social Engineering for Ransomware Breaches

    The hacker group Shiny Hunters claims to have stolen nearly one billion records from Salesforce and is demanding ransom from 39 companies, threatening to release the data by October 10, 2025, if not paid. Salesforce denies its platform was breached, attributing the data loss to social engineering...

    Read More »
  • Salesforce Users at Risk From Gainsight Supply Chain Attack

    Salesforce Users at Risk From Gainsight Supply Chain Attack

    A cybersecurity incident involving Gainsight's Salesforce connector potentially exposed customer data, prompting Salesforce to revoke access and remove Gainsight apps from AppExchange due to unusual activity. The attack, claimed by the Scattered Spider-ShinyHunters-Lapsus$ group, may lead to a de...

    Read More »
  • Hackers Stole Data From 200 Companies in Google-Linked Breach

    Hackers Stole Data From 200 Companies in Google-Linked Breach

    A major supply chain attack compromised data from over 200 organizations, with Google confirming theft from Salesforce instances through Gainsight applications, highlighting risks in interconnected digital ecosystems. The hacking group Scattered Lapsus$ Hunters claimed responsibility, targeting c...

    Read More »
  • Salesforce Customers Hit by Hackers in Data Extortion Attack

    Salesforce Customers Hit by Hackers in Data Extortion Attack

    A new hacking collective called Scattered LAPSUS$ Hunters is extorting Salesforce and its customers by stealing and threatening to release approximately one billion records from major organizations using the platform. The group, composed of members from Lapsus$, Scattered Spider, and ShinyHunters...

    Read More »
  • Salesforce AgentForce Vulnerability: What You Need to Know

    Salesforce AgentForce Vulnerability: What You Need to Know

    A critical vulnerability named ForcedLeak, rated 9.4 in severity, was discovered in Salesforce's AgentForce platform, allowing attackers to exfiltrate confidential CRM data through indirect prompt injection. The flaw highlights that autonomous AI agents like AgentForce create a larger attack surf...

    Read More »
  • San Francisco Tech Firms’ Police Protection Costs Revealed

    San Francisco Tech Firms’ Police Protection Costs Revealed

    Despite Elon Musk relocating X's headquarters due to crime concerns, other tech firms like Airbnb and Salesforce have paid the San Francisco Police Department over $1.1 million combined in 2024 for on-site armed security through the city's 10B program. The program, which allows entities to reques...

    Read More »
  • Allianz Life Data Breach: 1.1 Million Customers' Data Exposed

    Allianz Life Data Breach: 1.1 Million Customers' Data Exposed

    Allianz Life suffered a cybersecurity breach affecting 1.1 million individuals, compromising sensitive personal data including names, addresses, and Social Security numbers. The attack, attributed to the ShinyHunters group, exploited a cloud-based CRM platform using social engineering and malicio...

    Read More »
  • Top Cybersecurity Open-Source Tools for January 2026

    Top Cybersecurity Open-Source Tools for January 2026

    Open-source tools like OpenAEV and StackRox provide robust security solutions, enabling comprehensive adversary simulations and specialized Kubernetes security for diverse environments. Specialized auditing tools such as AuraInspector for Salesforce and code scanners like Bandit for Python help i...

    Read More »