Salesforce: Three Attack Vectors via Third Parties and Misconfiguration14. July 2026CybersecurityShinyHunters-linked attackers gain Salesforce access through legitimate OAuth channels: vishing calls, stolen tokens from third-party vendors (Salesloft, Gainsight, Klue), and exposed Aura endpoints—not via product vulnerabilities. Share on: