Vulnerabilities & Exploits · Misconfiguration
Attackers used a modified open-source AuraInspector to find guest-user permission gaps and extract data. ShinyHunters claims responsibility and reports hundreds of affected sites; Salesforce says the cause is customer misconfiguration, not a platform flaw.
6 sources · Mar 11
Help Net Security
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites - Help Net Security
Salesforce customers have, once again, been targeted by the ShinyHunters group - or, at least, it's what the group claims.
originalCyberScoop
Salesforce issues new security alert tied to third customer attack spree in six months
Researchers said the threat group behind the campaign is associated with ShinyHunters, an outfit that’s previously stolen data from Salesforce instances for extortion attempts.
originalThe Hacker News
Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool
Modified AuraInspector scans misconfigured Salesforce Experience Cloud sites, extracting CRM data and enabling targeted vishing campaigns.
originalPart of the PlainSec briefing for 2026-03-11
Every edition of this story: ShinyHunters Exploits Misconfigured Experience Cloud to Harvest CRM Data