ShinyHunters가 Salesforce 환경에 침투한 경로를 Microsoft가 분석했다.
Microsoft는 데이터 절취 그룹 ShinyHunters가 Salesforce 환경에 침투하는 세 가지 방법을 분석했다. 이들은 플랫폼의 취약점을 악용하지 않고도 기업 환경에 접근하는 방법을 찾았다. 대부분의 경우 OAuth 연결을 통해 이미 조직이 준 신뢰를 이용했다.
Microsoft analyzes three attack paths into Salesforce by ShinyHunters without exploiting platform flaws.
Microsoft has analyzed three attack paths that the data-extortion group ShinyHunters used to infiltrate Salesforce environments. These attackers did not exploit any flaws in the platform, instead leveraging the trust already extended by organizations, primarily through OAuth connections linking Salesforce to third-party apps and vendors.