Search

Find merged stories by title or summary.

Threat Actors & Campaigns
Emerging1 src

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked… Source https://databreaches.net/2026/09/23/canva-hacked-via-vendors-salesforce-instance-other-customers-affected-as-well/1post-1participantReadfulltopic

·Malware.news
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Endzone has just published a new victim : AT&T

Revenue: $125.6 billion Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP!

·Ransomware.live
Read →
AI Security
Emerging1 src

AI is changing what Salesforce security needs to govern

Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce. A Trust Relationship (Source: WithSecure) What trust means The paper describes trust as the belief that people, systems, information and connected services … More → The post AI is changing what Salesforce security needs to govern appeared first on Help Net Security .

·Help Net Security
Read →
DFIR
Emerging1 src

InfoSec News Nuggets – 09/01/2026

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related data records. McKesson says it discovered the intrusion on August 25 and that its investigation is still in its early stages, while the attackers claim they used vishing calls against employees to compromise Okta single sign-on accounts and pivot into Salesforce and Snowflake environments, demanding over $55 million after McKesson allegedly failed to respond.

·AboutDFIR
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Falcon has just published a new victim : Hayward Holdings

Pool & spa equipment · NYSE: HAYW - Our 848 GB extraction includes your Salesforce, 1+ million of each business and customer records with PII, distributor pricing lists, margin structures, detailed financial records, P&L statements, accounting ledgers, extensive personnel files, IT infrastructure blueprints, privileged account credentials, strategic board preparation materials and much more.

·Ransomware.live
Read →
Policy & Regulation
Emerging1 src

IBM, Salesforce and More Pledge to White House List of Eight AI Safety Assurances - TechRepublic

IBM, Salesforce and More Pledge to White House List of Eight AI Safety Assurances TechRepublic

·TechRepublic Cybersecurity
Read →
Vendors & Market
Emerging1 src

Salesforce gave every org the same free scanner. Attackers already know what it misses.

A defense every attacker can rehearse against isn't a defense. It's a false sense of security.

·Cybersecurity Dive
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Shinyhunters has just published a new victim : CyrusOne, LLC.

Update 23 Aug : We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12. 9 million Salesforce records along with: Sharepoint: (369. 6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders • More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.)

·Ransomware.live
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Emperador has just published a new victim : NetExam

NetExam (netexam. com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18. 1 MB • Sector: Education, Retail, Other]

·Ransomware.live
Read →
Threat Actors & Campaigns
Emerging1 src

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158. 220. 87. 79, hosted on a

·The Hacker News
Read →
AI Security
Emerging1 src

Business adoption of AI agents tripled this year - as measurable ROI emerges

Industries are finding the strategies that work best for their business needs, according to Salesforce's latest Agentic Enterprise Index.

·ZDNet Security
Read →
Vulnerabilities & Patches
Emerging1 src

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates. io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … More → The post Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June , and there are fears that they could have found a new target. Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack.

·CSO Online
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Shinyhunters has just published a new victim : Sharecare, Inc.

This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3. 4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. • Size: 25GB+ (compressed) • Updated: 13 August 2026 • SHA256: 195842b8a53e8d7fe63238dbed753c1c28a86034ca98f99527ef743528b6cc45

·Ransomware.live
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Shinyhunters has just published a new victim : Baxter International, Inc.

Over 7. 1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. • Updated: 14 Aug 2026 • Warning: FINAL WARNING PAY OR LEAK

·Ransomware.live
Read →
Vulnerabilities & Patches
Emerging1 src

Please hack responsibly.

President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat .

·The CyberWire
Read →
Vendors & Market
Emerging1 src

153GB of stolen credentials surface after LiteLLM supply chain attack

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global ethical disclosure effort,” Alon Gal, Hudson Rock’s co-founder and CTO, told Help Net Security. “We … More → The post 153GB of stolen credentials surface after LiteLLM supply chain attack appeared first on Help Net Security .

·Help Net Security
Read →
Threat Actors & Campaigns
Emerging1 src

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [... ]

·BleepingComputer
Read →
Threat Actors & Campaigns
Emerging1 src

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow - Dark Reading

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow Dark Reading

·Dark Reading
Read →
Threat Actors & Campaigns
Emerging1 src

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

·Dark Reading
Read →
Threat Actors & Campaigns
Emerging1 src

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

A newly identified threat actor is running a large-scale, long-running cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service Portals globally. Dubbed the “City-Forum Campaign” after a domain tied to the attacker’s infrastructure, the operation has been quietly siphoning data from telecommunications providers, banks, financial services firms, enterprise software vendors, and public-sector portals since at least March 2025. Unlike known cybercrime groups such as ShinyHunters, which typically abuse Salesforce’s legacy Aura framework via over-permissioned guest user accounts, this threat actor has engineered a more advanced approach. While the campaign continues to leverage high-volume Aura enumeration, it also targets Salesforce’s newer Lightning Web Runtime (LWR) sites through UI-API a data layer lacking public exploitation tooling or documented research.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world. The activity has not stopped, and there is more of it … More → The post A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months appeared first on Help Net Security .

·Help Net Security
Read →
Breaches & Ransomware
Emerging1 src

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .

·SecurityWeek
Read →
Vendors & Market
Emerging1 src

KlueセキュリティインシデントとRecorded Futureへの影響

以下のメッセージは、本日早い時間にRecorded Futureのお客様およびパートナーの皆様に共有されたものです。 Recorded Futureは、透明性と情報共有がサイバーセキュリティにおける最も強力なツールの一つであると長年信じてきました。それらは私たちの活動の根幹をなすものであり、組織が脅威を理解し、それに対して行動できるよう支援しています。同じ原則が私たち自身にも適用されます。 この考えに基づき、私たちが利用している第三者のマーケティングベンダーであるKlueに関する最近のセキュリティインシデントの詳細を共有いたします。このインシデントは、私たちおよび他の組織に影響を与えました。 発生した事象 2026年6月13日、Recorded FutureのCSIRTは、Klueが、Klueと他のマーケティングおよびセールスSaaSプラットフォームを接続するために使用されるインテグレーション層に対する不正アクセスを特定したとの通知を受けました。Klueによると、不正な活動は2026年6月12日に始まり、同日午前中に封じ込められました。 当社のセキュリティチームはその後独自の調査を実施し、KlueおよびKlueと統合されたすべてのサービスにわたるアクティビティログを相関分析しました。 入手可能なすべての証拠から、Recorded Futureが特に標的とされたのではなく、SalesforceとKlueとの間の侵害されたインテグレーション(連携機能)を利用していたことにより、偶発的に影響を受けたことが示唆されています。 Recorded Futureの独自システム、内部データベース、または顧客プラットフォームデータがアクセスまたは侵害された証拠はありません。 調査結果 調査により、SalesforceとKlueとの間のあるインテグレーションに関連する侵害されたOAuthトークンを経由して、Recorded FutureのSalesforceアカウントの一部が影響を受けたことを確認しました。

·Recorded Future
Read →
AI Security
Emerging1 src

Practical lessons from deploying AI securely at scale

When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least incomplete. The technology certainly matters, but after working with multiple enterprise AI initiatives, I’ve learned that the hardest security problems rarely come from the model itself. They emerge when AI becomes part of real business processes. An AI assistant doesn’t simply answer questions. In a single workflow, it might pull a customer record from Salesforce, open a ticket in ServiceNow and send an update through Microsoft 365 before anyone has finished reading the summary. Increasingly, it makes decisions before a human even notices, and that shift changes the threat model.

·CSO Online
Read →
Vendors & Market
Emerging1 src

Detecting the Klue supply chain attack in Salesforce instances

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

·Datadog Security Labs
Read →
Breaches & Ransomware
Emerging1 src

Ralph Lauren - 139,903 breached accounts

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

·Have I Been Pwned
Read →
Breaches & Ransomware
Emerging1 src

Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress

Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.

·Huntress Blog
Read →
Awareness
Emerging1 src

Mapping out your unknown: A threat hunter’s guide to Salesforce

In this post, we walk through different threats to Salesforce and how to detect them.

·Datadog Security Labs
Read →

You've reached the end of current stories for this search.