原标题: Salesforce Warns of Mass Theft From Misconfigured Experience Cloud Sites
第一项始终是图钉的来源。总体可信度是各份资料对上方所用开始和结束时间支持程度的加权平均;资料每比最新的一份旧 180 天,权重减半。
Salesforce 安全团队的文章日期为“2026 年 3 月 7 日”(发布于 UTC 22:48);FINRA[2]:“2026 年 3 月 7 日,Salesforce 报告称 ShinyHunters 正在积极利用配置不当的 Experience Cloud 访客用户配置文件。”
FINRA names ShinyHunters as the group exploiting misconfigured guest profiles and says the stolen data feeds phishing, vishing and extortion against firms and clients.
Salesforce[1] Ben's timeline of 2026 incidents: the 7 March blog, a 12 March trust-site post, and later breaches claimed by ShinyHunters at Loblaw, Hallmark, 7-Eleven, ADT and Brinks Home.
ShinyHunters told The Register it stole data from almost 400 websites and about 100 high-profile companies; Mandiant's CTO confirmed misuse of AuraInspector.
有遗漏或错误吗?用你自己的话说明:能佐证此图钉的链接、不同的开始或结束日期及理由,或缺失、有误的信息。AI 会对照此图钉的来源进行核实,搜索更好的来源,并添加任何支持你说法的页面。图钉自身的来源仍然最重要。