

Risky Business #795 -- How The Com is hacking Salesforce tenants
11 snips Jun 11, 2025
Alex Tilley, Global Threat Research Coordinator at Okta and former investigator for the Australian Federal Police, joins to discuss pressing cybersecurity concerns. They tackle the alarming trends in social engineering, particularly focusing on Salesforce vulnerabilities. Tilley shares insights on identifying North Korean tactics in job scams, underscoring the need for collaboration between security teams and HR. The conversation also highlights the rise of cybercrime dynamics and how organizations can enhance their defenses against evolving threats.
AI Snips
Chapters
Transcript
Episode notes
Salesforce OAuth Authorization Risk
- Attackers exploit Salesforce OAuth app authorization to siphon tenant data using social engineering.
- This threat exploits architectural weaknesses and user misunderstanding more than software vulnerabilities.
Cloud IP Origin Risks
- Origin network-based access controls are porous with cloud infrastructure use.
- Testing access from multiple cloud provider regions reveals unexpected elevated access.
North Korean Fake Job Tradecraft
- North Koreans develop advanced tradecraft to spoof legitimate software developer applicants.
- They study CVs, use fake job ads, and deploy malware to blend into remote job markets.