Back Scworld Salesforce Experience Cloud misconfigurations exploited by ShinyHunters | brief
Salesforce is alerting customers to a security issue affecting misconfigured Experience Cloud platforms, where hackers are exploiting guest accounts to access sensitive data. The ShinyHunters extortion gang claims responsibility for actively exploiting exposed instances to steal data, as reported by Bleeping Computer.
Attackers are leveraging a modified version of the open-source AuraInspector tool to target the /s/sfsites/aura API endpoint on misconfigured Salesforce Experience Cloud instances. This misconfiguration allows guest users unintended access to more data than they should have access to. Salesforce emphasizes that this is not a platform vulnerability but a result of customer-configured guest user settings granting excessive permissions.
The ShinyHunters gang claims to have compromised between 300 and 400 organizations, many in the cybersecurity sector, by exploiting these access control weaknesses. They reportedly found ways to bypass data query limitations, accelerating data theft.
Source: Bleeping Computer
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
