Skip to content
Breaking News
 2026-03-11 Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker – Krebs on Security  2026-03-11 What Boards Must Demand in the Age of AI-Automated Exploitation  2026-03-11 Iran war a melting pot for other cyber threats  2026-03-11 Google completes $32 billion acquisition of Wiz  2026-03-11 A 5-step approach to taming shadow AI
  • Home

Cybernoz – Cybersecurity News

Search

Overly permissive ‘guest’ settings put Salesforce customers at risk

 Cybernoz  March 11, 2026  Posted in CISOOnline
Share: XFacebookPinterestRedditVKDiggLinkedinMix

According to the advisory, the campaign specifically targets environments where three conditions exist. These include instances with guest profiles having excessive object or field permissions, organization-wide default access for external users is not set to private, and guest users are allowed to access public APIs. These conditions allow attackers to query data through Experience Cloud guest profiles.

Why Salesforce environments make tempting targets

Salesforce deployments are particularly attractive because of the sensitive data they hold and the complexity of their access models.

“Salesforce instances often contain highly sensitive customer data, including credentials and secrets that can be used for lateral movement,” said Vincenzo Lozzo, CEO and cofounder of SlashID. At the same time, he added, the platform’s layered permissions architecture, including profiles, permissions sets, sharing rules, and integrations, which are not very well understood and can make accidental overexposure easy.



Source link

Related Articles

ClickFix attackers using new tactic to evade detection, says Microsoft
ClickFix attackers using new tactic to evade detection, says Microsoft
Security-Tools für KI-Infrastrukturen – ein Kaufratgeber
Security-Tools für KI-Infrastrukturen – ein Kaufratgeber
insider threat shadow worker steal stealing theft data
Europa im Visier von Cyber-Identitätsdieben
PQC roadmap remains hazy as vendors race for early advantage
PQC roadmap remains hazy as vendors race for early advantage

Post navigation

OPSWAT debuts MetaDefender Aether combining sandboxing, ML scoring and threat hunting for perimeter security →
← Intigriti collaborates with PortSwigger to support ethical hacking excellence

Latest Posts

  • Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker – Krebs on Security
  • What Boards Must Demand in the Age of AI-Automated Exploitation
  • Iran war a melting pot for other cyber threats
  • Google completes $32 billion acquisition of Wiz
  • A 5-step approach to taming shadow AI

Copyright © 2026 Cybernoz - Cybersecurity News

Design by ThemesDNA.com