Threat actors have exploited overly permissive anonymous-user settings in publicly accessible Salesforce Experience Cloud environments to retrieve data through the /s/sfsites/aura endpoint. A modified version of the open-source Aura Inspector tool has been used to mass-scan sites and extract records where guest permissions permit access; exposed names and phone numbers can support subsequent phishing and vishing. Salesforce says the platform is not itself vulnerable—the exposure results from customer configuration—and Dutch authorities reported that these campaigns affected misconfigured environments from late 2025 into early 2026.
Researchers also identified multiple Mendix low-code applications with excessive rights assigned to anonymous or newly registered users. Automated scans and legitimate platform requests can collect sensitive data from such deployments, potentially enabling extortion; McGraw-Hill was cited publicly as an example in April 2026. Organizations should inventory internet-facing applications and access rights, enforce least privilege and private defaults, remove unnecessary anonymous access and self-registration, require MFA for administrators, and centralize logging and behavior-based detection for abnormal API activity.

Map this exposure pattern across your cloud, code, and identities.
6 events from the most recent confirmed update back to the earliest known activity.
McGraw-Hill was reportedly extorted after a misconfiguration exposed personal data, with attackers threatening to publish the information unless a ransom was paid.
DIVD announced that a large-scale scan had identified multiple misconfigured Mendix applications with excessive permissions for anonymous or newly registered users. Exposed information included names, contact details, addresses, customer data, and identity documents.
Mandiant published AuraInspector, an open-source tool intended to help Salesforce administrators identify Experience Cloud configuration errors.
Threat actors abused overly permissive guest-user configurations in Salesforce Experience Cloud environments, allowing unauthenticated queries through the Aura API. Salesforce said the exposure resulted from customer configuration errors rather than a platform vulnerability.
DIVD began investigating authorization misconfigurations in applications built on the Mendix low-code platform. The investigation focused on applications granting excessive access to anonymous or newly registered users.
Attackers began using a modified AuraInspector to mass-scan public Salesforce Experience Cloud sites via the /s/sfsites/aura endpoint and extract data where guest permissions permitted access. The responsible group claimed to have affected between 300 and 400 organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcesalesforce.com
Open sourcedivd.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.