Salesforce issues new security alert tied to third customer attack spree in six months

2026-03-11T14:51:43Z020ff22b21e218f8eb80f7f25b5b4051d81df6417b74b3bbc38f15f1b289e4e0
AI and cybercrimeAmazon injunctionExperience CloudFBIJavaMicrosoft Patch TuesdayPerplexitySalesforceShinyHuntersdata exfiltrationdata sovereigntyexecutive order on cybercrimeextortionnational cyber strategyopen-source supply chainpac4jransomwaresoftware security accountabilityvulnerabilityzero-day

What happened

Multiple CyberScoop stories: Salesforce issued a security alert after a third wave of attacks against Experience Cloud customers tied to a group associated with ShinyHunters that has exfiltrated Salesforce data for extortion. Researchers disclosed a critical vulnerability in the widely used Java security library pac4j that poses serious downstream risks to dependent applications (no widespread exploitation reported). Microsoft’s March Patch Tuesday fixed 83 issues with no publicly known actively exploited zero-days; the FBI emphasized that basic security hygiene remains essential even as AI is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
020ff22b21e218f8eb80f7f25b5b4051d81df6417b74b3bbc38f15f1b289e4e0
Enrichment time
2026-03-11T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.