As cited
Copy frozen at (site build).
breaches incidents
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.
Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.
Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.
- Source published
- First seen by Cybersecurity Tracker