Salesforce, the software company behind one of the best CRMs for sales, has released out a patch for its email services after security researchers discovered a zero-day vulnerability that allowed hackers to target Facebook users with a convincing phishing scam.The actively exploited bug was discovered by the team at Guardio Labs and has been dubbed “PhishForce”. It made use of a flaw in Salesforce’s “email-to-case” feature – which lets users automate the creation of tickets for customer queries – to send outbound emails purporting to be from Meta Platforms via the official “@case.salesforce.com” domain.Not only did these emails look genuine to the recipients, but they evaded Facebook’s built-in phishing detection defenses as well, once again highlighting how even the most robust antivirus software and related solutions can be duped by gaps in the security architecture of popular products. Get the latest tech news, straight to your inboxDon’t miss out on the top business tech news with Tech.co’s weekly highlights reel Please fill in your name Please fill in your email Please verify before subscribing. How the Salesforce Phishing Attack WorkedThe phony phishing emails were titled “Breach of Content Standards” and claimed to advise recipients of an account compromise and impending
Read More
Salesforce Email Hack Used To Bait Facebook Phishing Trap – Tech.co
