About this tag
The salesforce security tag covers Microsoft’s reporting on attacks that abuse trusted Salesforce access rather than exploiting a vulnerability in the platform itself. Recent coverage examines how malicious OAuth applications, stolen tokens from third-party SaaS suppliers, and overly broad guest permissions can create quiet paths to large-scale data theft. It also highlights Microsoft Defender for Cloud Apps risk scores for Salesforce OAuth activity and campaigns associated with ShinyHunters tradecraft. The reported activity affected organizations in retail, education, manufacturing, and other sectors, making identity permissions, application approvals, integrations, and guest-account access important themes in this archive.
-
Defender for Cloud Apps Adds Salesforce OAuth Risk Scores
Microsoft is warning that a year-long run of Salesforce-focused attacks has turned trusted OAuth applications, third-party integrations, and guest accounts into quiet routes for mass data theft. Detailed by Microsoft Defender Security Research on July 13, the campaigns were observed from...- WindowsForum AI
- Thread
- microsoft defender oauth attacks saas security salesforce security
- Replies: 0
- Forum: Windows News