Ad Code

Ticker

6/recent/ticker-posts

Sponsored by.

Chatbot AI, Voice AI and Employee AI. IndustryStandard.com - Become your own Boss!

Yehey.com - ShinyHunters-Linked Hackers Breach Salesforce Using OAuth Trust Exploits

Image courtesy by QUE.com

Microsoft has published new research mapping how attackers whose methods line up with the data-extortion group ShinyHunters spent the past year walking into corporate Salesforce environments without exploiting a single platform vulnerability, instead abusing the OAuth trust connections that tie Salesforce to surrounding third-party apps and integrations. The campaigns ran from mid-2025 into mid-2026 and involved three distinct techniques, all specifically designed to generate traffic that reads as ordinary, trusted use rather than an intrusion. The research lands the same week a notorious ransomware group claimed responsibility for a cyberattack on the Orleans Parish Sheriff’s Office, and as Acronis researchers charted INC ransomware’s evolution into one of 2026’s most prolific cybercrime operations, with no fewer than 830 claimed victims since August 2023.

Why Trust-Based Salesforce Attacks Are So Hard to Catch

The fundamental challenge Microsoft’s research highlights is that when access comes from a real, authorized user who genuinely approved a connected app, or from an integration the organization already explicitly trusts, the resulting traffic looks like ordinary business use to standard sign-in and authentication monitoring. Attackers exploiting this dynamic do not need to break anything; they simply need to convince a legitimate user, through social engineering, to extend trust to a connection the attacker controls, at which point the attacker inherits whatever access that connection is permitted.

Microsoft worked directly with Salesforce to roll out new detection and governance tooling specifically addressing this activity, reflecting several important lessons for any organization relying on OAuth-connected SaaS ecosystems:
  • Authentication logs alone are insufficient — since the traffic originates from legitimately authorized connections, standard sign-in monitoring will not flag this activity as anomalous
  • OAuth connection review needs to become a routine governance practice — organizations should periodically audit exactly which third-party apps and integrations have been granted OAuth access to core platforms like Salesforce, not simply at initial approval time
  • Purpose-built detection tooling is increasingly necessary — Microsoft’s collaboration with Salesforce to build governance tooling specifically for this attack pattern signals that generic platform security monitoring was insufficient to catch it

Orleans Parish Sheriff’s Office Confirms Ransomware Attack

A notorious ransomware group has claimed responsibility for a cyberattack against the Orleans Parish Sheriff’s Office, continuing the persistent pattern of ransomware groups targeting local government and law enforcement agencies that has run throughout 2026, alongside the earlier small Ohio county incident and Chelan County, Washington’s extended multi-week disruption covered in previous weeks. Law enforcement agencies represent particularly sensitive ransomware targets given the criminal justice and detention-related data these systems typically hold, where operational disruption carries genuine public safety implications beyond the standard data theft and extortion concerns.

INC Ransomware’s Rise Illustrates the Post-LockBit Landscape

Acronis researcher Darrel Virtusio has charted INC ransomware’s evolution from a nascent ransomware-as-a-service operation into one of 2026’s most prolific cybercrime groups, now claiming no fewer than 830 victims since its emergence in August 2023. The research specifically attributes this growth to the disruption of LockBit and the shutdown of BlackCat, which created opportunities for INC to expand as displaced affiliates migrated to alternative ransomware operations seeking a new platform to continue operating from.

This pattern, where successful law enforcement disruption of one major ransomware operation directly fuels the growth of its competitors as displaced affiliates simply relocate, represents a genuinely persistent structural challenge in ransomware disruption strategy: individual takedowns can shift market share within the ransomware ecosystem without necessarily reducing the total volume of attacks or affiliate talent actively operating within it.

Anubis Affiliates Blend In Using Legitimate Remote Access Tools

Separately, researchers have documented that Anubis ransomware-as-a-service affiliates repeatedly abuse legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, specifically to blend in with normal IT activity while maintaining control of compromised victim systems. This technique mirrors the same underlying logic behind the Salesforce OAuth trust abuse covered above: rather than deploying obviously malicious custom tooling that security software might flag, attackers increasingly favor legitimate, widely-trusted administrative tools that generate traffic indistinguishable from routine IT operations.

What Organizations Should Do Now

Given Microsoft’s Salesforce OAuth trust research, organizations should implement periodic review cycles for all third-party apps and integrations connected to core SaaS platforms, treating initial OAuth approval as the beginning of an ongoing governance relationship rather than a one-time security decision. Security teams should specifically evaluate whether their current monitoring can distinguish between legitimate and attacker-abused usage of common remote access tools like ScreenConnect and Zoho Assist, given how systematically Anubis affiliates have exploited exactly this blind spot. And any local government or law enforcement agency should treat the Orleans Parish incident as a reminder to specifically stress-test incident response plans for scenarios involving detention and public-safety-critical system disruption, not just standard data breach notification procedures.

Microsoft’s Salesforce research and the Anubis remote-access-tool findings both point toward the same defining pattern in 2026’s ransomware landscape: attackers increasingly succeed not by breaking systems, but by exploiting the trust those systems already extend to legitimate users and tools, a pattern considerably harder for traditional security monitoring to catch than a conventional exploit.


Published by MAJ.COM AI Autonomous
Email: [email protected]
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.




Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous

Articles published by QUE.COM Intelligence via Yehey.com website.

Post a Comment

0 Comments

Comments

Ad Code