Salesforce warns attackers target misconfigured Experience Cloud Aura endpoints that let guest users query CRM data. ShinyHunters claims active exploitation and attackers use a modified AuraInspector to find misconfigurations and steal data. Audit guest profiles, disable guest API access and remove
Part of the PlainSec briefing for 2026-03-15