Salesforce Zero-Day Exploited to Phish Facebook Credentials
Salesforce Zero-Day Exploited to Phish Facebook Credentials Elizabeth MontalbanoContributor, Dark ReadingThe cyberattacks used the legitimate Salesforce.com domain by chaining the vulnerability to an abuse of Facebook's Web games platform, slipping past email protections.Attackers were recently spotted exploiting a zero-day flaw in Salesforce's email and SMTP services in a sophisticated phishing campaign aimed at stealing credentials from Facebook users.Guardio researchers detected cyberattackers sending targeted phishing emails with @salesforce.com addresses using the legitimate Salesforce infrastructure. An investigation...