< ciso
brief />
Tag Banner

All news with #salesforce tag

92 articles

Weekly ThreatsDay: GhostJacking and New Attacks

πŸ“° This ThreatsDay Bulletin aggregates a week of security updates across cloud services, AI agents, malware, data breaches, scams, and novel attack techniques. It summarizes campaigns like City-Forum targeting guest access in Salesforce and ServiceNow, the ShipMonk customer data exposure, and Cursor's pre-trust code execution flaw. The bulletin also highlights vishing platforms, AI agent hijacking (GhostJacking), defensive prompt-injection use, and other noteworthy incidents.
read more β†’

ShinyHunters claims Brinks Home breach and data threat

πŸ”’ Brinks Home disclosed a security intrusion identified on July 20 and activated incident response procedures while engaging leading forensics experts. The company said alarm monitoring and system functionality were not impacted. Extortion group ShinyHunters claims to have stolen millions of Salesforce records and threatened to publish the data, though BleepingComputer has not verified the claims.
read more β†’

Klue Breach Reveals New Third‑Party Identity Risks

πŸ”’ The 2026 Klue compromise began as a SaaS supply‑chain breach and escalated when a second criminal group claimed to have stolen data from the initial extortion crew. Attackers exploited a forgotten service account and harvested OAuth tokens, enabling broad Salesforce API access and extensive data extraction. The incident underscores how identity and delegated application permissions now constitute the primary attack surface, challenging traditional perimeter defenses and ransom decision models.
read more β†’

The SaaS blind spot: visibility gaps in cloud apps

πŸ” Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps β€” audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews β€” can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more β†’

Microsoft maps year-long OAuth access campaigns

πŸ”Ž Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more β†’

Defending SaaS OAuth Abuse Targeting Salesforce

πŸ”’ Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more β†’

Klue OAuth breach expands as Icarus claims attack

πŸ”’ Klue confirmed an incident on June 12 in which attackers used a compromised legacy credential to obtain OAuth tokens connecting Klue to third-party platforms, including Salesforce. The company says customer content stored in Klue was not impacted and that the breach was limited to integrations; affected credentials and tokens were revoked and CrowdStrike engaged. Cybersecurity firms ReliaQuest and Huntress reported extensive Salesforce data exfiltration, and the Icarus extortion group has publicly claimed responsibility.
read more β†’

Salesforce disables Klue app after OAuth breach

πŸ”’ Salesforce has disabled the Klue Battlecards app integration after unusual activity tied to a Klue security incident on June 11, 2026, which may have allowed unauthorized access to some customer data. Klue says attackers used a compromised legacy credential to obtain OAuth tokens and access connected third-party platforms, while Salesforce emphasizes the issue stemmed from the app connection and not its platform. Klue and customers like Huntress are investigating, revoking tokens, and remediating impacts.
read more β†’

Infinite Campus Salesforce Breach Exposes Staff Data

πŸ”’ Infinite Campus disclosed a Salesforce data theft in March that exposed personal information for school staff across its K‑12 customer base. The attacker, linked to groups known for targeting Salesforce instances, allegedly leaked a 1.2GB archive. Have I Been Pwned found data from 137,100 accounts, including names, emails, job titles and contact details. Infinite Campus said most exposed items appear to be directory information commonly published by schools.
read more β†’

Charter Communications breach exposes 4.9M accounts

πŸ”’ The ShinyHunters extortion gang claims to have stolen personal details from 4.9 million Charter Communications accounts after a vishing attack in early April that compromised an employee's Microsoft Entra account. Charter confirmed the incident but says no sensitive PII or CPNI was exfiltrated, while Have I Been Pwned verified leaked records containing names, emails, addresses, phone numbers and some job titles. The group published stolen Salesforce data after a ransom was refused.
read more β†’

Charter Confirms Breach After ShinyHunters Extortion

πŸ”’ Charter Communications confirmed a data breach after the ShinyHunters extortion group claimed to have stolen millions of customer records. The company says it is notifying authorities and maintains that No sensitive personal information (PI) or CPNI was exfiltrated. ShinyHunters alleges the intrusion began via a vishing attack that compromised an employee's Microsoft Entra account and allowed access to Salesforce data.
read more β†’

7‑Eleven Breach Exposes Personal Data of 185K

πŸ” 7‑Eleven disclosed that an unauthorized party accessed franchisee document systems on April 8, 2026, resulting in a data theft. Have I Been Pwned analyzed the leaked files and found 185,300 unique email addresses and accompanying personal details, including names, dates of birth, phone numbers, and physical addresses. The ShinyHunters extortion gang claimed responsibility after publishing a large archive they said came from 7‑Eleven's Salesforce environment.
read more β†’

7-Eleven Confirms Data Breach Claimed by ShinyHunters

πŸ”’ 7-Eleven disclosed that an unauthorized party accessed systems used to store franchisee documents on April 8, 2026, and began notifying affected individuals on May 1. The company has not provided details on the number of affected people or specific data types exposed. The extortion group ShinyHunters claimed responsibility on April 17, alleging the theft of over 600,000 records from the company's Salesforce environment and later leaking a 9.4GB archive after ransom talks failed. 7-Eleven said it launched an investigation but has not commented further.
read more β†’

ADT Breach: ShinyHunters Exposes 5.5M Records, Partial IDs

πŸ”’ ShinyHunters stole personal data for about 5.5 million ADT customers and posted an 11GB archive on a dark web leak site after a failed extortion. ADT says it detected the intrusion on April 20 and that accessed information was largely limited to names, phone numbers, and addresses, with a small number of records including DOBs and last-four SSNs/Tax IDs. The group claims the attack began with a vishing compromise of an employee's Okta SSO account that enabled theft from the company's Salesforce instance; ADT reports no payment data or customer security systems were affected.
read more β†’

ADT Confirms Customer Data Breach After ShinyHunters Threat

πŸ”’ ADT confirmed unauthorized access to customer and prospective customer data detected on April 20, saying it terminated the intrusion and opened an investigation. The company reported that stolen information was limited to names, phone numbers, and addresses, with a small subset including dates of birth and the last four digits of SSNs or Tax IDs. ADT emphasized no payment data or customer security systems were affected. ShinyHunters claims over 10 million records were taken after a vishing attack that allegedly compromised an employee’s Okta SSO and accessed Salesforce data.
read more β†’

Copilot and Agentforce Vulnerable to Prompt Injection

πŸ” Capsule Security researchers discovered prompt-injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that allow attackers to inject malicious instructions via standard input fields. In Copilot, a crafted payload in a SharePoint form field can overwrite agent instructions and exfiltrate SharePoint data; Microsoft has released a patch (CVE-2026-21520). In Agentforce, attackers can embed directives in public lead forms that an agent with email or query capabilities may execute, enabling broad CRM data leakage.
read more β†’

McGraw Hill Salesforce Misconfiguration Exposes 13.5M Accounts

πŸ”’ The ShinyHunters extortion group has published data tied to 13.5 million McGraw Hill user accounts after exploiting a misconfiguration in a Salesforce-hosted webpage. McGraw Hill confirmed unauthorized access to a limited set of data and said its internal systems, courseware and customer databases were not affected. Leaked files β€” over 100GB by Have I Been Pwned β€” contain names, email addresses, phone numbers and physical addresses that could be used for targeted spear‑phishing.
read more β†’

Prompt-Injection Flaws in Copilot Studio and Agentforce

⚠️ Security researchers at Capsule Security disclosed prompt-injection vulnerabilities in Microsoft Copilot Studio and Salesforce Agentforce that let attackers embed malicious instructions in public form fields. Crafted inputs submitted via SharePoint or lead forms can override agent instructions and trigger data exfiltration to attacker-controlled endpoints. Microsoft patched the SharePoint-related issue (CVE-2026-21520) with a 7.5 CVSS score; Salesforce acknowledged the problem but described the vector as configuration-specific. Researchers warn that treating external inputs as trusted undermines autonomous agent security and urge input validation, least-privilege, and stricter outbound controls.
read more β†’

McGraw-Hill Confirms Limited Data Exposure via Salesforce

πŸ”’ McGraw-Hill says unauthorized actors accessed a limited set of data hosted on a Salesforce webpage after a platform misconfiguration. The company emphasized this did not involve unauthorized entry to its Salesforce accounts, customer databases, courseware, or internal systems, and that exposed information was non-sensitive. McGraw-Hill secured the pages, engaged external cybersecurity experts, and is working with Salesforce to strengthen protections amid an extortion claim by ShinyHunters.
read more β†’

Infinite Campus Warns of Salesforce Breach, Extortion

πŸ”’ Infinite Campus warned customers of a data breach following an extortion claim from a threat actor who said they accessed an employee's Salesforce account. The company says the exposed information appears to be primarily public directory data for school staff and that no customer databases were accessed. Infinite Campus declined to engage with the attacker and has disabled certain customer-facing services while scanning potentially affected records and notifying impacted districts.
read more β†’