Product
Salesforce
- First Reported
- Sep 15, 2026
- Latest Reported
- Oct 1, 2026
Reported Context (2)
- Each year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day. Report Traces ShinyHunters’ Six-Year Evolution and Changing Attack Tactics
- Threat actors initiated the attack by submitting a seemingly innocuous inquiry through Salesforce. After the sales team followed up, the threat actors replied that a subsequent email would be sent to "sign an NDA". The GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens
CVE (1)
Malware (1)
Threat Actors (22)
MITRE ATT&CK (18)
Vendors (11)
Products (16)
Tools (8)
Industries (7)
Countries (12)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.