On August 2, 2023, Guardio Labs researchers published a report to disclose a highly advanced phishing campaign that took advantage of a zero-day vulnerability in Salesforce's email services and SMTP servers where cybercriminals skillfully combined this exploit with legacy issues in Facebook's retired Web Games platform to avoid detection. According to researchers, the attackers went to great lengths to make their phishing emails appear legitimate, using Salesforce's "@salesforce.com" domain and infrastructure while disguising the emails as if they were from Meta. Once clicked, the link redirected users to a fake landing page, where their account credentials and two-factor authentication codes were captured. In addition, attackers, by hosting their phishing kit within Facebook's apps platform, apps[.]facebook[.]com, allowed the emails to bypass anti-spam and anti-phishing filters by including legitimate links and an apparently valid @salesforce.com email address. Despite the fact that Facebook's Web Games functionality was retired in July 2020, the attackers were able to take advantage of the platform's legacy support for earlier games. In addition, they bypassed Salesforce's validation process by creating an Email-to-Case routing address with the salesforce.com domain, deceiving the system into validating their false email address. Moreover, when Guardio Labs made the responsible disclosure to Salesforce on June 28, 2023, Salesforce promptly addressed the zero-day vulnerability by implementing additional checks to prevent the use of @salesforce.com email addresses.
Apple has revealed that it blocked more than $11 billion in fraudulent App Store transactions over the past six years, including over $2.2 billion in potentially fraudulent activit...
Trend Micro has disclosed an actively exploited zero-day vulnerability affecting its Apex One endpoint security platform used in enterprise Windows environments. The flaw, tracked ...
Drupal has warned administrators that threat actors are actively attempting to exploit a highly critical SQL injection vulnerability tracked as CVE-2026-9082. The flaw impacts Drup...