Vendor
City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access
2 TTPs 2 IOCsAn unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.
Klue Security Incident Leads to Recorded Future Salesforce Data Compromise
3 TTPsA third-party marketing vendor, Klue, experienced unauthorized access to its integration layer, which connects to other SaaS platforms like Salesforce, leading to the compromise of an OAuth token and subsequent unauthorized access to Recorded Future's Salesforce account, where business data fields including customer contact names, email addresses, and potentially business contract information were accessed.
ShinyHunters OAuth Abuse Targeting SaaS Applications
6 TTPsShinyHunters, and related threat actor Storm-3138, conducted campaigns between mid-2025 and mid-2026 by employing voice phishing, supply chain compromise, and misconfigured guest access to abuse trusted OAuth relationships in SaaS applications like Salesforce, leading to unauthorized access, data exfiltration, and persistence.
Microsoft Security Updates — July 2026
10 CVEs 227 IOCsRoundup of Microsoft security advisories published in July 2026.
ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records
2 rules 7 TTPs 2 CVEs 13 IOCsThe financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.
UNC6671 BlackFile Vishing Extortion Campaign Targeting Microsoft 365 and Okta
2 rules 8 TTPs 5 IOCsUNC6671, operating under the "BlackFile" brand, conducts a sophisticated extortion campaign targeting organizations through voice phishing (vishing) and single sign-on (SSO) compromise, using adversary-in-the-middle (AiTM) techniques to bypass MFA and exfiltrate sensitive corporate data.
Salesforce Marketing Cloud Engagement Argument Injection Vulnerability (CVE-2026-2298)
2 rules 1 TTP 1 IOCCVE-2026-2298 is an argument injection vulnerability in Salesforce Marketing Cloud Engagement that allows Web Services Protocol Manipulation in versions prior to January 30th, 2026.