<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Salesforce Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Salesforce.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Claude Chrome extension flaw lets malicious extensions trigger AI actions</title><link>https://bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions</link><guid isPermaLink="false">cst-2716</guid><description>A vulnerability in Anthropic's Claude Chrome extension allows malicious extensions to simulate user clicks and trigger predefined AI actions without explicit user consent. The flaw could be exploited to abuse Claude's access to connected services including Gmail, Google Docs, Google Calendar, and Salesforce.</description><pubDate>Thu, 16 Jul 2026 19:26:07 GMT</pubDate></item><item><title>ValorC3 extends SaaS protection with immutable cloud backups</title><link>https://helpnetsecurity.com/2026/07/16/valorc3-backup-as-a-service-baas</link><guid isPermaLink="false">cst-2685</guid><description>ValorC3 Data Centers released a fully managed backup service for SaaS applications including Microsoft 365, Entra ID, and Salesforce, featuring immutable backup copies to protect against deletion, corruption, and ransomware. The service addresses a common misconception that cloud vendors automatically provide data backup protection. Recent governance research indicates 80% of organizations have encountered at least one cloud security incident.</description><pubDate>Thu, 16 Jul 2026 11:48:49 GMT</pubDate></item><item><title>Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths</title><link>https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html</link><guid isPermaLink="false">cst-2455</guid><description>Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.</description><pubDate>Tue, 14 Jul 2026 06:19:24 GMT</pubDate></item><item><title>Defending SaaS-based applications against ShinyHunters OAuth abuse</title><link>https://microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse</link><guid isPermaLink="false">cst-2451</guid><description>Microsoft identified ShinyHunters-associated threat actors conducting campaigns from mid-2025 to mid-2026 that abused OAuth relationships to compromise Salesforce and other SaaS applications across retail, education, and manufacturing sectors. The attackers used voice phishing to trick users into authorizing malicious apps, exploited supply chain compromises in third-party integrations like Salesloft, and leveraged misconfigured guest access to gain persistence and exfiltrate customer relationship management data. These intrusion paths operated within legitimate OAuth workflows, allowing the threat actors to inherit user privileges and evade conventional authentication detection without exploiting any Salesforce vulnerability.</description><pubDate>Mon, 13 Jul 2026 22:02:41 GMT</pubDate></item><item><title>Scope of Salesforce Attacks Expands as Icarus Leaks Data</title><link>https://darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data</link><guid isPermaLink="false">cst-116</guid><description>Attackers who breached application vendor Klue obtained OAuth tokens that enabled unauthorized access to Salesforce data belonging to Klue's customers. The scope of affected organizations has expanded beyond initial disclosures as additional victims are identified.</description><pubDate>Tue, 23 Jun 2026 20:44:09 GMT</pubDate></item><item><title>Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress</title><link>https://huntress.com/blog/klue-breach-investigation</link><guid isPermaLink="false">cst-669</guid><description>Klue, a competitive intelligence platform, experienced a security breach that exposed Salesforce data from multiple vendors and customers, including Huntress. The incident affected an undetermined number of organizations that relied on Klue's services. Details about the breach scope and remediation efforts remain limited.</description><pubDate>Thu, 18 Jun 2026 07:00:00 GMT</pubDate></item><item><title>Klue Integration Abused in Salesforce Data Theft</title><link>https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft</link><guid isPermaLink="false">cst-2117</guid><description>Attackers compromised the Klue integration in Salesforce to exfiltrate customer relationship management (CRM) data by abusing OAuth tokens and automated REST API queries. The activity follows a pattern seen in prior Salesforce third-party compromises affecting Salesloft, Drift, and Gainsight throughout 2025 and 2026. A Telegram account claiming to be ShinyHunters took responsibility, though attribution remains unconfirmed.</description><pubDate>Wed, 17 Jun 2026 09:00:00 GMT</pubDate></item><item><title>ShinyHunters Fast-Tracks SaaS Access with Subdomain Impersonation</title><link>https://reliaquest.com/blog/threat-spotlight-shinyhunters-fast-tracks-saas-access-subdomain-impersonation</link><guid isPermaLink="false">cst-2202</guid><description>ShinyHunters is shifting from lookalike domain registration to subdomain impersonation tactics, hiding target organization branding in subdomains of generic SSO-themed domains to evade traditional domain monitoring. The group combines this with mobile-optimized phishing lures, outsourced spam and voice operations, and reused stolen CRM/ERP data to accelerate compromise of SaaS environments through session theft and help-desk MFA resets.</description><pubDate>Thu, 26 Feb 2026 18:00:00 GMT</pubDate></item><item><title>Wiz goes (even more) global</title><link>https://wiz.io/blog/wiz-goes-even-more-global</link><guid isPermaLink="false">cst-1831</guid><description>Wiz, a cloud security company, raised an additional $250 million in funding during the first half of 2021, bringing its total funding to $350 million. The capital injection from investors including Sequoia and Salesforce enabled the company to expand its headcount from 25 to 120 employees during that period.</description><pubDate>Tue, 14 Sep 2021 16:59:28 GMT</pubDate></item><item><title>Salesforce Ventures, Blackstone, and Aglaé Join Team Wiz!</title><link>https://wiz.io/blog/salesforce-ventures-blackstone-and-algae-join-team-wiz</link><guid isPermaLink="false">cst-1838</guid><description>Wiz completed its Series B funding round with an additional $120 million investment from Salesforce Ventures and Blackstone, along with participation from Aglaé Ventures. The round was previously announced in March and has now closed with these additional backers joining the effort.</description><pubDate>Thu, 10 Jun 2021 12:37:52 GMT</pubDate></item></channel></rss>