Skip to content
Threat Feed

Vendor

Salesforce

7 briefs RSS
high advisory

City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access

An unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.

Salesforce Aura +2 data-exfiltration cloud-security reconnaissance guest-access-abuse
2t 2i
high advisory

Klue Security Incident Leads to Recorded Future Salesforce Data Compromise

A third-party marketing vendor, Klue, experienced unauthorized access to its integration layer, which connects to other SaaS platforms like Salesforce, leading to the compromise of an OAuth token and subsequent unauthorized access to Recorded Future's Salesforce account, where business data fields including customer contact names, email addresses, and potentially business contract information were accessed.

Klue +1 data-breach supply-chain cloud-security saas-security oauth
3t
high threat

ShinyHunters OAuth Abuse Targeting SaaS Applications

ShinyHunters, and related threat actor Storm-3138, conducted campaigns between mid-2025 and mid-2026 by employing voice phishing, supply chain compromise, and misconfigured guest access to abuse trusted OAuth relationships in SaaS applications like Salesforce, leading to unauthorized access, data exfiltration, and persistence.

Salesforce +4 ShinyHunters oauth-abuse saas supply-chain vishing data-exfiltration persistence cloud
6t
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +516 roundup
10c 227i updated
high threat

ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records

The financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.

PoC Oracle E-Business Suite +9 ShinyHunters ransomware data-theft extortion cloud-security threat-actor-group credential-stuffing
2r 7t 2c 13i updated
high threat

UNC6671 BlackFile Vishing Extortion Campaign Targeting Microsoft 365 and Okta

UNC6671, operating under the "BlackFile" brand, conducts a sophisticated extortion campaign targeting organizations through voice phishing (vishing) and single sign-on (SSO) compromise, using adversary-in-the-middle (AiTM) techniques to bypass MFA and exfiltrate sensitive corporate data.

Microsoft 365 +5 UNC6671 vishing extortion aitm credential-theft data-exfiltration sso
2r 8t 5i
critical advisory

Salesforce Marketing Cloud Engagement Argument Injection Vulnerability (CVE-2026-2298)

CVE-2026-2298 is an argument injection vulnerability in Salesforce Marketing Cloud Engagement that allows Web Services Protocol Manipulation in versions prior to January 30th, 2026.

Marketing Cloud Engagement argument-injection web-services salesforce
2r 1t 1i