Salesforce Zero-Day Flaw Exploited In Facebook Phishing Attacks
- Joseph K

- Aug 6, 2023
- 1 min read
As elaborated in a detailed post from Guardio Labs, their researchers detected an active Facebook phishing campaign exploiting a Salesforce SMTP server zero-day. Specifically, the vulnerability, identified as “PhishForce,” allows an adversary to evade the existing Salesforce sender verification measures. Hence, an attacker may exploit the flaw to generate phishing emails exploiting the legit Salesforce domain and infrastructure.
Comments