Threat actors use custom AuraInspector to harvest data from Salesforce systems
2026-03-10T14:51:48Z•c77f8c93b97d35d29f4c426153f5b06ed7dc9a950e1cccbc10735171428235bd
2FA phishingAuraInspectorCISACognizantEricssonExperience CloudFBI phishing warningIvanti EPMKnown Exploited VulnerabilitiesOmnissa Workspace OneRussia-linked activitySalesforceSignal compromise attempts','WhatsApp compromise attempts'SolarWindsTriZettoTycoondata breachdata exfiltrationlaw enforcement takedownmass scanningmisconfigurationphishing-as-a-servicesupply chain compromisethird‑party breachzoning permit scams
What happened
Collection of security reports (March 2026) highlighting multiple active threats and high-impact vulnerabilities: attackers are mass‑scanning Salesforce Experience Cloud sites using a modified AuraInspector to exploit misconfigurations and harvest data; CISA added multiple flaws (including Ivanti EPM, SolarWinds, Omnissa Workspace One and others) to its Known Exploited Vulnerabilities catalog; Ericsson US and Cognizant’s TriZetto Provider Solutions disclosed breaches exposing employee/customer and ~3.4M patient records respectively. Law enforcement disrupted the Tycoon 2FA phishing-as-a‑ervice
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c77f8c93b97d35d29f4c426153f5b06ed7dc9a950e1cccbc10735171428235bd
- Enrichment time
- 2026-03-10T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.