< ciso
brief />
Tag Banner

All news with #salesforce tag

95 articles

Amazon Bedrock adds Salesforce and Zendesk connectors

πŸ”— AWS announced native Salesforce and Zendesk data source connectors for Amazon Bedrock Managed Knowledge Base, enabling direct synchronization of Salesforce knowledge articles and Zendesk help center articles and community posts. The connectors remove the need for custom ingestion pipelines by handling crawling, metadata extraction, and incremental sync using instance credentials. This streamlines building RAG-based AI agents and assistants grounded in up-to-date support and product knowledge.
read more β†’

AWS Glue adds archived Salesforce records capture

πŸ”” AWS Glue zero-ETL integrations for Salesforce now capture archived records and expose their status via the isArchived field, providing a complete replica of Salesforce data for analytics and reporting. This applies automatically to new integrations and is backfilled for existing integrations with no reconfiguration or schema changes. The feature is available in all AWS Commercial and AWS GovCloud (US) Regions where AWS Glue zero-ETL for Salesforce is supported.
read more β†’

Amazon Quick: Build Custom Apps with Natural Language

πŸ› οΈ Amazon Quick is now generally available, enabling users to create custom applications by describing them in natural language. It connects to existing systems like Salesforce, Jira, Microsoft 365, databases, and data warehouses while honoring identity and access controls. Apps update automatically as source data changes and can be published to specific users or an entire organization. Available to Plus, Professional, and Enterprise customers starting September 1, 2026.
read more β†’

Weekly ThreatsDay: GhostJacking and New Attacks

πŸ“° This ThreatsDay Bulletin aggregates a week of security updates across cloud services, AI agents, malware, data breaches, scams, and novel attack techniques. It summarizes campaigns like City-Forum targeting guest access in Salesforce and ServiceNow, the ShipMonk customer data exposure, and Cursor's pre-trust code execution flaw. The bulletin also highlights vishing platforms, AI agent hijacking (GhostJacking), defensive prompt-injection use, and other noteworthy incidents.
read more β†’

ShinyHunters claims Brinks Home breach and data threat

πŸ”’ Brinks Home disclosed a security intrusion identified on July 20 and activated incident response procedures while engaging leading forensics experts. The company said alarm monitoring and system functionality were not impacted. Extortion group ShinyHunters claims to have stolen millions of Salesforce records and threatened to publish the data, though BleepingComputer has not verified the claims.
read more β†’

Klue Breach Reveals New Third‑Party Identity Risks

πŸ”’ The 2026 Klue compromise began as a SaaS supply‑chain breach and escalated when a second criminal group claimed to have stolen data from the initial extortion crew. Attackers exploited a forgotten service account and harvested OAuth tokens, enabling broad Salesforce API access and extensive data extraction. The incident underscores how identity and delegated application permissions now constitute the primary attack surface, challenging traditional perimeter defenses and ransom decision models.
read more β†’

The SaaS blind spot: visibility gaps in cloud apps

πŸ” Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps β€” audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews β€” can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more β†’

Microsoft maps year-long OAuth access campaigns

πŸ”Ž Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more β†’

Defending SaaS OAuth Abuse Targeting Salesforce

πŸ”’ Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more β†’

Klue OAuth breach expands as Icarus claims attack

πŸ”’ Klue confirmed an incident on June 12 in which attackers used a compromised legacy credential to obtain OAuth tokens connecting Klue to third-party platforms, including Salesforce. The company says customer content stored in Klue was not impacted and that the breach was limited to integrations; affected credentials and tokens were revoked and CrowdStrike engaged. Cybersecurity firms ReliaQuest and Huntress reported extensive Salesforce data exfiltration, and the Icarus extortion group has publicly claimed responsibility.
read more β†’

Salesforce disables Klue app after OAuth breach

πŸ”’ Salesforce has disabled the Klue Battlecards app integration after unusual activity tied to a Klue security incident on June 11, 2026, which may have allowed unauthorized access to some customer data. Klue says attackers used a compromised legacy credential to obtain OAuth tokens and access connected third-party platforms, while Salesforce emphasizes the issue stemmed from the app connection and not its platform. Klue and customers like Huntress are investigating, revoking tokens, and remediating impacts.
read more β†’

Infinite Campus Salesforce Breach Exposes Staff Data

πŸ”’ Infinite Campus disclosed a Salesforce data theft in March that exposed personal information for school staff across its K‑12 customer base. The attacker, linked to groups known for targeting Salesforce instances, allegedly leaked a 1.2GB archive. Have I Been Pwned found data from 137,100 accounts, including names, emails, job titles and contact details. Infinite Campus said most exposed items appear to be directory information commonly published by schools.
read more β†’

Charter Communications breach exposes 4.9M accounts

πŸ”’ The ShinyHunters extortion gang claims to have stolen personal details from 4.9 million Charter Communications accounts after a vishing attack in early April that compromised an employee's Microsoft Entra account. Charter confirmed the incident but says no sensitive PII or CPNI was exfiltrated, while Have I Been Pwned verified leaked records containing names, emails, addresses, phone numbers and some job titles. The group published stolen Salesforce data after a ransom was refused.
read more β†’

Charter Confirms Breach After ShinyHunters Extortion

πŸ”’ Charter Communications confirmed a data breach after the ShinyHunters extortion group claimed to have stolen millions of customer records. The company says it is notifying authorities and maintains that No sensitive personal information (PI) or CPNI was exfiltrated. ShinyHunters alleges the intrusion began via a vishing attack that compromised an employee's Microsoft Entra account and allowed access to Salesforce data.
read more β†’

7‑Eleven Breach Exposes Personal Data of 185K

πŸ” 7‑Eleven disclosed that an unauthorized party accessed franchisee document systems on April 8, 2026, resulting in a data theft. Have I Been Pwned analyzed the leaked files and found 185,300 unique email addresses and accompanying personal details, including names, dates of birth, phone numbers, and physical addresses. The ShinyHunters extortion gang claimed responsibility after publishing a large archive they said came from 7‑Eleven's Salesforce environment.
read more β†’

7-Eleven Confirms Data Breach Claimed by ShinyHunters

πŸ”’ 7-Eleven disclosed that an unauthorized party accessed systems used to store franchisee documents on April 8, 2026, and began notifying affected individuals on May 1. The company has not provided details on the number of affected people or specific data types exposed. The extortion group ShinyHunters claimed responsibility on April 17, alleging the theft of over 600,000 records from the company's Salesforce environment and later leaking a 9.4GB archive after ransom talks failed. 7-Eleven said it launched an investigation but has not commented further.
read more β†’

ADT Breach: ShinyHunters Exposes 5.5M Records, Partial IDs

πŸ”’ ShinyHunters stole personal data for about 5.5 million ADT customers and posted an 11GB archive on a dark web leak site after a failed extortion. ADT says it detected the intrusion on April 20 and that accessed information was largely limited to names, phone numbers, and addresses, with a small number of records including DOBs and last-four SSNs/Tax IDs. The group claims the attack began with a vishing compromise of an employee's Okta SSO account that enabled theft from the company's Salesforce instance; ADT reports no payment data or customer security systems were affected.
read more β†’

ADT Confirms Customer Data Breach After ShinyHunters Threat

πŸ”’ ADT confirmed unauthorized access to customer and prospective customer data detected on April 20, saying it terminated the intrusion and opened an investigation. The company reported that stolen information was limited to names, phone numbers, and addresses, with a small subset including dates of birth and the last four digits of SSNs or Tax IDs. ADT emphasized no payment data or customer security systems were affected. ShinyHunters claims over 10 million records were taken after a vishing attack that allegedly compromised an employee’s Okta SSO and accessed Salesforce data.
read more β†’

Copilot and Agentforce Vulnerable to Prompt Injection

πŸ” Capsule Security researchers discovered prompt-injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that allow attackers to inject malicious instructions via standard input fields. In Copilot, a crafted payload in a SharePoint form field can overwrite agent instructions and exfiltrate SharePoint data; Microsoft has released a patch (CVE-2026-21520). In Agentforce, attackers can embed directives in public lead forms that an agent with email or query capabilities may execute, enabling broad CRM data leakage.
read more β†’

McGraw Hill Salesforce Misconfiguration Exposes 13.5M Accounts

πŸ”’ The ShinyHunters extortion group has published data tied to 13.5 million McGraw Hill user accounts after exploiting a misconfiguration in a Salesforce-hosted webpage. McGraw Hill confirmed unauthorized access to a limited set of data and said its internal systems, courseware and customer databases were not affected. Leaked files β€” over 100GB by Have I Been Pwned β€” contain names, email addresses, phone numbers and physical addresses that could be used for targeted spear‑phishing.
read more β†’