Salesforce Sites Scanned by Custom AuraInspector
Threat actors are actively scanning Salesforce sites, particularly those utilizing Experience Cloud, using a modified AuraInspector tool. Salesforce’s Cybersecurity Operations Center warns that these adversaries aim to exploit misconfigurations and access sensitive data. AuraInspector, originally developed by Google/Mandiant, is an open-source auditing tool for Salesforce’s Aura and Experience Cloud applications. It evaluates exposure risks by simulating unauthenticated user scenarios to pinpoint misconfigurations in access controls.
The attack primarily targets overly permissive guest user settings, allowing access to critical CRM data. Salesforce stresses this activity does not stem from a platform vulnerability but rather from customer misconfigurations. The company urges organizations to review and secure their Experience Cloud settings promptly.
Salesforce attributes the campaign to groups like ShinyHunters, emphasizing the importance of restricting public access and monitoring APIs and logs. For more details on securing your systems, read the complete article at the provided link.
Threat actors use custom AuraInspector to harvest data from Salesforce systems
