Scope of Salesforce Attacks Expands as Icarus Leaks Data
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers‘ Salesforce data.
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers‘ Salesforce data.
Klue’s Battlecards is now the third integrated application that has been compromised to steal customers‘ Salesforce data, and victims include Huntress, the cybersecurity vendor.
Two recently fixed prompt injections in Salesforce Agentforce and Microsoft Copilot would have enabled an external attacker to leak sensitive data.
Web Searches For Archives Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282 FBI Flash Alert: Salesforce Attacks The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access […]