<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Salesforce on CuraSec</title><link>https://curasec.metacog.co.kr/tags/salesforce/</link><description>Recent content in Salesforce on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 11:57:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/salesforce/index.xml" rel="self" type="application/rss+xml"/><item><title>City-Forum campaign steals data from misconfigured Salesforce/ServiceNow portals</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-city-forum-data-theft-attacks-target-salesforce-servicenow-p/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-city-forum-data-theft-attacks-target-salesforce-servicenow-p/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Salesforce Experience Cloud and ServiceNow are near-universal enterprise platforms; the attack exploits data exposed to anonymous portal users — a misconfiguration, not a zero-day. Audit both platforms now for anonymous/guest access permissions and tighten portal visibility settings before an attacker runs the same tooling against your instance.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or ATT&amp;amp;CK mappings are available yet, but the campaign uses custom tooling against anonymous portal endpoints. Queue detection work for anomalous unauthenticated API calls and bulk record retrieval in Salesforce Experience Cloud and ServiceNow access logs.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Salesforce and ServiceNow portals are in most enterprise environments, and this active campaign targets data exposed through anonymous access — a configuration gap with real breach-disclosure implications. This week, confirm whether your portal configurations restrict anonymous access and what customer or employee data could be exposed.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Maps Three Salesforce OAuth Attack Paths Used by ShinyHunters</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> No platform CVE to patch — the attack surface is over-trusted OAuth connections and third-party integrations. Audit all connected apps in your Salesforce org, revoke unused OAuth grants, and review third-party vendor permissions this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft has detailed three concrete attack paths from an active, year-long campaign — hunt for anomalous OAuth authorization events and unusual connected-app activity in Salesforce audit logs going back at least 12 months to check for prior compromise.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> ShinyHunters is an active data-extortion group and this campaign abuses third-party SaaS trust, not software flaws — confirm your organization&amp;rsquo;s Salesforce OAuth integrations are inventoried, brief leadership on third-party SaaS risk exposure, and ask your Salesforce-connected vendors for attestation of their OAuth hygiene.&lt;/li>
&lt;/ul></description></item></channel></rss>