INTEL_REPORT
The Hacker News · published 7/14/2026, 6:19:24 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In Mic…
https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html
sha256:a5eb04dcb187fb02ab1cc2921142ed4be97cdb48b1fa3e3798163f9990eb7aef
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.