FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ShinyHunters Targets Salesforce Environments via Sophisticated OAuth Abuse Campaign

Between mid-2025 and mid-2026, threat actor ShinyHunters (UNC604/UNC6395) targeted Salesforce and interconnected SaaS environments using an identity-centric attack chain. The group bypassed perimeter defenses by utilizing vishing and supply chain compromises to gain initial access, subsequently exploiting misconfigured guest permissions to authorize malicious OAuth applications. By securing long-lived OAuth tokens and manipulating trusted SaaS-to-SaaS integrations, the actors achieved persistent, high-privilege access to sensitive enterprise data. This campaign avoided CVE-based exploitation, focusing instead on the abuse of OAuth trust mechanisms to facilitate large-scale data exfiltration while evading traditional vulnerability scanners.


LINK COPIED TO CLIPBOARD