元のタイトル: Salesforce Warns of Mass Theft From Misconfigured Experience Cloud Sites
最初の項目は常にピンの出典です。全体の確度は、各資料が上記の開始・終了時刻をどれだけ強く裏付けているかの加重平均です。最新の資料より180日古くなるごとに、重みは半分になります。
Salesforce Securityの投稿の日付は「2026年3月7日」(UTC 22時48分公開)。FINRA[2]によれば、「2026年3月7日、Salesforceは、ShinyHuntersが設定不備のExperience Cloudゲストユーザープロファイルを積極的に悪用していると報告した」。
FINRA names ShinyHunters as the group exploiting misconfigured guest profiles and says the stolen data feeds phishing, vishing and extortion against firms and clients.
Salesforce[1] Ben's timeline of 2026 incidents: the 7 March blog, a 12 March trust-site post, and later breaches claimed by ShinyHunters at Loblaw, Hallmark, 7-Eleven, ADT and Brinks Home.
ShinyHunters told The Register it stole data from almost 400 websites and about 100 high-profile companies; Mandiant's CTO confirmed misuse of AuraInspector.
足りない点や誤りがありますか? このピンを裏付けるリンク、別の開始日・終了日とその理由、欠けている情報や誤っている情報を、自由に書いてください。AIがこのピンの出典と照らし合わせ、より良い情報源を探し、裏付けとなるページがあれば参考資料として追加します。ピン自身の出典が引き続き最も重視されます。