2025 Event
Tech Theater 1
6:25 pm - 6:40 pm, Monday, October 27
Tech Theater Presented by Vorlon Security: From Vishing to Exfiltration: Closing Critical OAuth and API Blind Spots in Your SaaS Ecosystem
About

This presentation breaks down the attack methodology used by ShinyHunters to compromise Salesforce environments at well-known organizations. Participants will see how attackers weaponized legitimate OAuth flows and API integrations to steal sensitive data while remaining virtually invisible to traditional security controls. The session also explains why API-based exfiltration is difficult to detect without specialized monitoring like Vorlon and provides actionable steps teams can implement immediately to protect Salesforce and other SaaS applications.

In this session you will:

  • Learn how attackers abuse legitimate authentication flows to target Salesforce
  • Understand why most organizations lack sufficient visibility into SaaS API activity
  • Explore how continuous monitoring of both human and non-human identities, with focus on OAuth applications, strengthens defense
Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Kris Tanaka
VP, Event Programming

InfoSec World
Stay Informed
Join our mailing list for the latest news on InfoSec World 2025.