Threat actors use custom AuraInspector to harvest data from Salesforce systems

2026-03-10T14:51:48Zc77f8c93b97d35d29f4c426153f5b06ed7dc9a950e1cccbc10735171428235bd
2FA phishingAuraInspectorCISACognizantEricssonExperience CloudFBI phishing warningIvanti EPMKnown Exploited VulnerabilitiesOmnissa Workspace OneRussia-linked activitySalesforceSignal compromise attempts','WhatsApp compromise attempts'SolarWindsTriZettoTycoondata breachdata exfiltrationlaw enforcement takedownmass scanningmisconfigurationphishing-as-a-servicesupply chain compromisethird‑party breachzoning permit scams

What happened

Collection of security reports (March 2026) highlighting multiple active threats and high-impact vulnerabilities: attackers are mass‑scanning Salesforce Experience Cloud sites using a modified AuraInspector to exploit misconfigurations and harvest data; CISA added multiple flaws (including Ivanti EPM, SolarWinds, Omnissa Workspace One and others) to its Known Exploited Vulnerabilities catalog; Ericsson US and Cognizant’s TriZetto Provider Solutions disclosed breaches exposing employee/customer and ~3.4M patient records respectively. Law enforcement disrupted the Tycoon 2FA phishing-as-a‑ervice

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c77f8c93b97d35d29f4c426153f5b06ed7dc9a950e1cccbc10735171428235bd
Enrichment time
2026-03-10T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Threat actors use custom AuraInspector to harvest data from Salesforce systems · Baitaphish