AuraInspector: Open-source tool to audit Salesforce Aura access control misconfigurations

Google and its Mandiant threat intelligence unit have released AuraInspector, an open-source tool aimed at auditing data access paths in Salesforce Experience Cloud applications. The tool focuses on the Aura framework, which underpins many Salesforce u… Continue reading AuraInspector: Open-source tool to audit Salesforce Aura access control misconfigurations

Armenia probes alleged sale of 8 million government records on hacker forum

Daryna Antoniuk reports: Hackers are offering for sale what they claim is a large trove of Armenian government-related data, prompting officials in Yerevan to open an investigation into a potential breach. The alleged seller, using the alias dk0m, said… Continue reading Armenia probes alleged sale of 8 million government records on hacker forum

Noction adds automatic anomaly detection to IRP v4.3 for faster DDoS mitigation

Noction has released Noction Intelligent Routing Platform (IRP) v4.3, delivering new capabilities in automated DDoS detection, routing safety, and operational control for modern IP networks. A key highlight of IRP v4.3 is the introduction of Automatic … Continue reading Noction adds automatic anomaly detection to IRP v4.3 for faster DDoS mitigation

Browser-in-the-Browser phishing is on the rise: Here’s how to spot it

Browser-in-the-Browser (BitB) phishing attacks are on the rise, with attackers reviving and refining the technique to bypass user skepticism and traditional security controls. BitB phishing: Dangerous and effective For BitB phishing, attackers create a… Continue reading Browser-in-the-Browser phishing is on the rise: Here’s how to spot it