FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

Phishers Exploit Salesforce's Email Services Zero-Day in Targeted Facebook Campaign

By: THN β€” August 2nd 2023 at 12:55
A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce's email services, allowing threat actors to craft targeted phishing messages using the company's domain and infrastructure. "Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook's Web Games platform,"
☐ β˜† βœ‡ The Hacker News

Beware of Ghost Sites: Silent Threat Lurking in Your Salesforce Communities

By: Ravie Lakshmanan β€” May 31st 2023 at 13:00
Improperly deactivated and abandoned SalesforceΒ SitesΒ andΒ CommunitiesΒ (aka Experience Cloud) could pose severe risks to organizations, leading to unauthorized access to sensitive data. Data security firm Varonis dubbed the abandoned, unprotected, and unmonitored resources β€œghost sites.” β€œWhen these Communities are no longer needed, though, they are often set aside but not deactivated,” Varonis
❌