LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ai

AI is changing what Salesforce security needs to govern

Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those acti

zeroday.news ·

The increasing integration of artificial intelligence and automation into business processes, particularly within Salesforce environments, necessitates a re-evaluation of traditional cybersecurity and governance practices. Existing security frameworks, which typically focus on identities, permissions, access controls, and configurations, are insufficient to address the complexities introduced by AI agents, APIs, and interconnected systems.

A new framework, called Trust Mapping, has been proposed to help organizations understand and manage the evolving security landscape. This framework defines "trust" as the belief that individuals, systems, information, and connected services will operate as expected within a business workflow. It recognizes that these trust relationships can extend across various entities, including human users, AI agents, APIs, and external platforms.

Each trust relationship has a defined responsibility, scope, and boundary, outlining what is being relied upon, where that trust applies, and its limitations. These relationships are also underpinned by assumptions about the conditions that enable the reliance. As AI and automation take on more tasks without direct human intervention, these trust relationships can span multiple connected tools and processes.

The Trust Mapping Framework examines trust across five key domains: entities (who or what participates), information (what data is used), connections (how trust is established or extended), actions (how trust is exercised), and system outcomes (what results the workflow produces). This framework is applicable to various Salesforce processes, including Agentforce, Headless 360, third-party SaaS applications, and AI-assisted workflows.

The framework proposes a two-stage process: Discovery and Governance. Trust Mapping Discovery aims to identify the specific trust relationships that enable a business workflow to function. This involves defining their responsibilities, scope, boundaries, and supporting assumptions. For instance, scenarios might include a salesperson using an AI model like Claude through Headless 360 to analyze Salesforce data, a customer support request handled by Agentforce and reviewed by a human, or a discontinued Salesforce integration with active credentials.

Following Discovery, the Governance stage assesses whether these identified trust relationships remain appropriate, justified, and aligned with business intent, and if they introduce risks requiring mitigation. This assessment considers the five domains of the framework, focusing on visibility, ownership, purpose, monitoring, and review. Organizations evaluate if the right people and systems have appropriate authority, if information remains reliable, and if connections and actions stay within their intended limits. They also examine workflow outcomes and their potential impact on other processes.

Based on this assessment, a trust relationship can be maintained, modified, restricted, or removed, and additional controls or increased monitoring can be implemented. Governance relies on evidence such as changes in permissions or OAuth scopes, security incidents, audit findings, threat intelligence, AI behavior and model evaluations, business process changes, and operational data. The level of review is proportional to the workflow's complexity, criticality, regulatory requirements, connectivity, and autonomy.

A key concept is "trust drift," which occurs when a trust relationship deviates from its original purpose, scope, limits, or supporting assumptions. Examples include unused but active credentials, excessive access, outdated information, and unvalidated AI-generated recommendations.

Trust Mapping is an ongoing process, as relationships can change with the introduction of new integrations and AI agents, vendor replacements, employee role changes, project retirements, or shifts in information reliance. Therefore, Discovery and Governance may need to be repeated. This approach complements existing security practices like security posture management, threat modeling, and identity governance by adding a workflow-level perspective on dependencies, their rationale, boundaries, and underlying assumptions.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]