Security researchers warn that poorly configured Salesforce Experience Cloud environments are being exploited to extract sensitive data through guest accounts. According to BleepingComputer, attackers linked to the ShinyHunters group are targeting the platform’s /s/sfsites/aura API using a modified AuraInspector tool. By abusing excessive guest permissions, the group claims it accessed data from hundreds of organizations, highlighting persistent risks tied to cloud configuration errors.
