{"id":104747,"date":"2026-07-14T00:20:10","date_gmt":"2026-07-14T00:20:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/104747\/"},"modified":"2026-07-14T00:20:10","modified_gmt":"2026-07-14T00:20:10","slug":"defending-saas-based-applications-against-shinyhunters-oauth-abuse","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/104747\/","title":{"rendered":"Defending SaaS-based applications against ShinyHunters OAuth abuse"},"content":{"rendered":"<p>\t\tIn this article<\/p>\n<p class=\"wp-block-paragraph\">In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply chain compromise, and misconfigured guest access to target customer SaaS-based applications such as Salesforce instances. The threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.<\/p>\n<p class=\"wp-block-paragraph\">Three primary intrusion paths were observed including vishing techniques targeting OAuth consent, supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight, and exploitation of misconfigured guest access. Abuse of these access paths led to inherited user and application privileges, allowing successful enumeration and querying of customer relationship management (CRM) records while evading conventional authentication detections. These intrusion paths often led to persistent access and exfiltration of data at scale. This tradecraft highlights how a single entry point can rapidly expand to greater enterprise impacts.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft observed activity associated with these techniques in many tenants from various industries such as retail, education and manufacturing. These findings\u00a0reinforce the importance of monitoring OAuth-connected applications, validating third-party integrations, reviewing guest access configurations, and enabling Salesforce event monitoring. Leveraging this data, Microsoft consulted with Salesforce to improve granularity in telemetry for Defender for Cloud Apps with near-real-time detection, offering connected application attribution and expanded application permission insights. This activity was not the result of a vulnerability inherent to Salesforce. Rather, the threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.<\/p>\n<p>Attack chain overview<\/p>\n<p class=\"wp-block-paragraph\">Threat actor campaigns targeting Salesforce customers and using tradecraft associated with ShinyHunters pose a high-impact risk to sensitive data and downstream SaaS ecosystems. These campaigns abuse OAuth trust relationships to operate within pre-existing, legitimate workflows.<a id=\"_msocom_1\"\/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_676_image-5.webp\" alt=\"\" class=\"wp-image-148667 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_676_image-5.webp\"\/>Figure 1. Commonly observed attack paths for SaaS applications.<\/p>\n<p class=\"wp-block-paragraph\">Observed activity can be grouped into three primary intrusion paths:<\/p>\n<p>Voice\u2011phishing-driven OAuth consent abuse<\/p>\n<p class=\"wp-block-paragraph\">In campaigns beginning in mid-2025, the threat actors conducted vishing attacks impersonating IT support personnel.\u00a0Threat actors socially engineered employees into authorizing attacker-controlled connected apps within their Salesforce tenant. In several confirmed cases, threat actors guided users through the OAuth consent workflow to grant access to a malicious application disguised as a legitimate Salesforce Data Loader tool. After users granted consent, these highly privileged OAuth applications enabled threat actors to perform API calls on behalf of the victim user, facilitating:<\/p>\n<p>Enumeration of Salesforce instances belonging to targeted organizations<\/p>\n<p>Persistent access to Salesforce CRM data<\/p>\n<p>Possible lateral movement into other SaaS platforms through discovered credentials<\/p>\n<p class=\"wp-block-paragraph\">This intrusion path exploits the OAuth authorization flow of trusted SaaS services rather than relying on malware or credential replay. Threat actors exfiltrate data through sanctioned application access inherited from user privileges.<\/p>\n<p>SaaS supply\u2011chain compromise targeting trusted integrations<\/p>\n<p class=\"wp-block-paragraph\">Following initial access campaigns, threat actors\u00a0 escalated into supply\u2011chain-driven attacks targeting third\u2011party SaaS vendors offering popular solutions that integrate with Salesforce, often using OAuth tokens. In August 2025, <a href=\"https:\/\/trust.salesloft.com\/a\/659c728a-e351-4d28-a690-7395f99cdc80?lng=en\" rel=\"nofollow noopener\" target=\"_blank\">compromised Salesloft Drift credentials<\/a> enabled attackers to obtain connection secrets used by downstream SaaS applications, enabling the use of OAuth tokens in multiple customer Salesforce instances.<\/p>\n<p class=\"wp-block-paragraph\">A subsequent <a href=\"https:\/\/www.gainsight.com\/blog\/supporting-our-customers-and-community-an-update-on-the-recent-security-advisory-related-to-gainsight\/\" rel=\"nofollow noopener\" target=\"_blank\">campaign<\/a> in November 2025 targeted Gainsight-published applications integrated with Salesforce, allowing attackers to leverage trusted external connections to maintain persistent API access in multiple Salesforce customer instances. These activities often appeared indistinguishable from legitimate integration behavior. Threat actors performed discovery, bulk data queries, and mass exfiltration of sensitive CRM records, including accounts, contacts, and service case data, without generating traditional sign-in anomalies.<br \/>More recently, in June 2026, the market intelligence platform Klue experienced an <a href=\"https:\/\/klue.com\/blog\/an-update-on-recent-klue-security-incident\" rel=\"nofollow noopener\" target=\"_blank\">incident<\/a> where a threat actor, Storm-3138, gained access to its system.\u00a0 Credentials used to access Salesforce customer instances were used in the same fashion, to discover, query, and exfiltrate data.<\/p>\n<p>Guest access used for exfiltration<\/p>\n<p class=\"wp-block-paragraph\">Over recent months, Microsoft observed an increase in suspicious guest-user activity targeting Salesforce Aura endpoints across multiple organizations. In these incidents, threat actors leveraged unauthenticated access to Aura framework functionality and used GraphQL-based Aura requests to systematically query and retrieve data. While the activity did not exploit a software vulnerability, it took advantage of misconfigured guest-user permissions to gain unauthorized access to data. By chaining Aura requests and leveraging GraphQL queries, the actors were able to circumvent standard record-retrieval limitations and extract significantly larger volumes of data than would typically be accessible to guest users. All three intrusion paths relied on inheriting trusted application or user privileges, making malicious activity difficult to distinguish from normal operations. The resulting quiet persistence and large-scale data access highlight the need for stronger detection, visibility, and governance of OAuth-connected applications and guest user accounts.<\/p>\n<p>Improving visibility into Salesforce OAuth abuse<\/p>\n<p class=\"wp-block-paragraph\">For customers using <a href=\"https:\/\/www.salesforce.com\/platform\/shield\/\" rel=\"nofollow noopener\" target=\"_blank\">Salesforce Shield: Event Monitoring<\/a>, the upgraded\u00a0<a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-cloud-apps\/protect-salesforce\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Defender for Cloud Apps Salesforce connector<\/a> onboards the Real-Time Event Monitoring (RTEM) framework, enabling faster detection and investigation of Salesforce-based attacks.<\/p>\n<p class=\"wp-block-paragraph\">Investigations into these campaigns exposed a recurring challenge for security teams: malicious activity often appeared indistinguishable from legitimate Salesforce usage because threat actors operated through trusted identities, approved OAuth applications, and authorized integrations. Traditional authentication-focused detections frequently provided limited visibility into the resulting application activity.<\/p>\n<p class=\"wp-block-paragraph\">To improve investigation and detection of these scenarios, Microsoft expanded Salesforce visibility in Defender for Cloud Apps through additional event telemetry, connected application attribution, and enhanced application permissions insights. These capabilities help security teams identify suspicious OAuth activity, investigate potentially compromised integrations, and better understand how access was obtained and used within customer Salesforce instances.<\/p>\n<p class=\"wp-block-paragraph\">Key capabilities include:<\/p>\n<p>Near-real-time visibility into Salesforce security and activity events.<\/p>\n<p>Connected application attribution, including application identity and granted OAuth scopes.<\/p>\n<p>Expanded identity, session, and API activity context to support investigations.<\/p>\n<p>Improved correlation within Microsoft Defender to help identify suspicious activity spanning identities, applications, and SaaS environments.<\/p>\n<p class=\"wp-block-paragraph\">Together with Salesforce Shield: Event Monitoring, these capabilities help security teams investigate suspicious OAuth activity, validate the legitimacy of connected applications, and better understand the potential impact of a compromise.<a id=\"_msocom_1\"\/><\/p>\n<p>New posture and governance capabilities for connected OAuth apps<\/p>\n<p class=\"wp-block-paragraph\">While improved detection is critical, recent incidents have also highlighted the need for stronger preventive controls and ongoing governance of OAuth-connected applications. To address this, Microsoft Defender introduces new posture capabilities for connected and external client apps in Salesforce. Security teams can gain visibility into each OAuth app and its non-human identity, prioritize risk, and reduce the attack surface.<\/p>\n<p>Deep visibility into app permissions and access<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Defender provides comprehensive visibility into all Salesforce-integrated connected and external client apps, including granted OAuth scopes and privileges.<a id=\"_msocom_9\"\/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_461_image-6.webp\" alt=\"\" class=\"wp-image-148668 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_461_image-6.webp\"\/>Figure 2. Complete permission visibility for Salesforce connected apps and external client apps.<\/p>\n<p>Highly privileged apps<\/p>\n<p class=\"wp-block-paragraph\">Security teams often struggle to identify applications with powerful administrative or sensitive permissions. The highly privileged apps insight highlights applications that have been granted elevated scopes, enabling quick identification of apps that may pose significant risk.<\/p>\n<p class=\"wp-block-paragraph\">Additionally, security teams can use permission-based filters to identify apps with specific high-risk scopes and validate whether such access is justified.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_712_image-7.webp\" alt=\"\" class=\"wp-image-148669 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988409_712_image-7.webp\"\/>Figure 3. Identity inventory to identify highly privileged Salesforce apps.<\/p>\n<p>Unused apps<\/p>\n<p class=\"wp-block-paragraph\">Organizations often create applications for temporary or one-time use, but those applications are rarely removed afterward. These unused apps continue to retain permissions, creating unnecessary exposure. With the recent changes, Defender now allows security teams to identify applications that have been inactive for extended periods (for example, 90 days or more), making it easy to review and revoke access where appropriate to reduce the attack surface.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-8.webp\" alt=\"\" class=\"wp-image-148670 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-8.webp\"\/>Figure 4. Identity inventory to discover unused Salesforce apps.<\/p>\n<p>Risk-based prioritization of connected apps<\/p>\n<p class=\"wp-block-paragraph\">To further streamline investigation and response, Defender introduces a comprehensive risk scoring model for connected applications. Each application is assigned a numerical risk score [0-100] based on multiple risk indicators, such as usage patterns, permission sensitivity, and behavioral signals. This allows security teams to prioritize efforts effectively and focus on applications that require immediate attention. Security teams can create custom policies based on risk thresholds to trigger alerts, actions, and notifications.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988410_880_image-9.webp\" alt=\"\" class=\"wp-image-148671 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1783988410_880_image-9.webp\"\/>Figure 5. Use actionable insights to identify apps exceeding a defined risk threshold.<\/p>\n<p>Risk score investigation<\/p>\n<p class=\"wp-block-paragraph\">To further investigate the specific Non-Human identity risk details, the factors contributing to the risk score are available in Non-Human Identities Risk score tab.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-10.webp\" alt=\"\" class=\"wp-image-148672 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-10.webp\"\/>Figure 6. Detailed risk insights explaining factors contributing to the risk score.<\/p>\n<p>Mitigation and protection guidance<\/p>\n<p class=\"wp-block-paragraph\">Microsoft\u00a0recommends the following mitigations to reduce the impact of this threat. Check the recommendations card for the deployment status of\u00a0monitored\u00a0mitigations.\u00a0\u00a0<\/p>\n<p>Microsoft Defender detections<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Defender customers can refer to the list of applicable detections including new detections powered by the upgraded Microsoft Defender for Cloud Apps Salesforce connector. Microsoft Defender coordinates detection, prevention, investigation, and response for endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<p class=\"wp-block-paragraph\">Customers with provisioned access can also use <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-xdr\/security-copilot-in-microsoft-365-defender\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Security Copilot in Microsoft Defender<\/a> to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.<\/p>\n<p>Tactic\u00a0Observed activity\u00a0Microsoft Defender coverage\u00a0Initial AccessA user\u2019s Salesforce session was hijacked and usedSalesforce detected a possibly hijacked user sessionCredential AccessA user was the target of credential stuffing activitySalesforce detected a successful credential stuffing attackLateral MovementA user with a very high risk score is signing into Salesforce via SSOSalesforce SSO sign-in by high-risk userCollection \/ ExfiltrationAPI-heavy access, report export, and scraping patterns; potential multi-SaaS expansion depending on victim footprint.\u2013 Possible Salesforce scraping activity <br \/>\u2013 Salesforce detected a user performing anomalous API activity <br \/>\u2013 Salesforce detected a user performing anomalous report activityCollection \/ ExfiltrationAnomalous behavior from Salesforce Connected Apps\u2013 Salesforce Connected App activity from a new IP address <br \/>\u2013 Salesforce Connected App activity involving new <br \/>\u2013 Salesforce entity Salesforce Connected App activity involving new endpoint(s)Collection \/ ExfiltrationGuest user activity associated with the AuraInspector frameworkSuspicious Salesforce Aura ActivityCollection \/ ExfiltrationAnomalous behavior from a guest userSalesforce detected a guest user performing anomalous activity<\/p>\n<p>Threat intelligence reports\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Microsoft customers can use the following reports in Microsoft products to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer Salesforce instances.<\/p>\n<p>Advanced hunting<\/p>\n<p class=\"wp-block-paragraph\">NOTE:\u00a0The sample queries let you search one week of events. To inspect events and hunt for threat actor-related indicators over a longer period, go to the\u00a0Advanced Hunting\u00a0page &gt;\u00a0Query\u00a0tab, and use the calendar dropdown to set the time range to\u00a0Last 30 days (the maximum for raw data). <\/p>\n<p class=\"wp-block-paragraph\">Hunt for Salesforce connected-app activity from suspicious infrastructure<\/p>\n<p>CloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where ActionType in (&#8220;ApiTotalUsage&#8221;, &#8220;API Event&#8221;)<br \/>\n| extend ConnectedAppId = tostring(<br \/>\n    coalesce(<br \/>\n        RawEventData.CONNECTED_APP_ID, \/\/ from ApiTotalUsage<br \/>\n        RawEventData.ConnectedAppId \/\/ from API Event<br \/>\n    )<br \/>\n)<br \/>\n| where isnotempty(ConnectedAppId)<br \/>\n| where array_length(UncommonForUser) &gt; 0 \/\/ at least 1 attribute is flagged as uncommon<\/p>\n<p class=\"wp-block-paragraph\">Hunt for API activity associated with connected apps and relevant user ids<\/p>\n<p>CloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where ActionType in (&#8220;ApiTotalUsage&#8221;, &#8220;API Event&#8221;)<br \/>\n| extend SalesforceUserId=coalesce(tostring(RawEventData.USER_ID), tostring(RawEventData.UserId))<br \/>\n| extend ConnectedAppName=tostring(RawEventData.CONNECTED_APP_NAME)  \/\/ Connected App Name is not available on the ApiEvent event<br \/>\n| summarize count() by AccountObjectId, AccountId, AccountDisplayName, SalesforceUserId, IPAddress, UserAgent, ConnectedAppName<\/p>\n<p class=\"wp-block-paragraph\">Hunt for anomalous report export \/ large data access<\/p>\n<p>CloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where ActionType  == &#8220;ReportExport&#8221;<br \/>\n| extend SalesforceUserId = tostring(RawEventData.USER_ID)<br \/>\n| summarize Events=count() by AccountObjectId, AccountId, AccountName, SalesforceUserId, IPAddress, UserAgent<\/p>\n<p class=\"wp-block-paragraph\">Pivot from a suspicious connected app (name\/id) to impacted users and actions<\/p>\n<p>CloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where RawEventData has &#8220;&#8221;<br \/>\n| project Timestamp, AccountId, AccountDisplayName, ActionType, IPAddress, UserAgent, RawEventData<br \/>\n| order by Timestamp desc<\/p>\n<p class=\"wp-block-paragraph\">Audit queries to verify what objects users are accessing<\/p>\n<p>CloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where ActionType == &#8220;UniqueQuery&#8221;<br \/>\n| extend<br \/>\n    QueryText = tostring(RawEventData.QUERY_IDENTIFIER), \/\/ Full query text<br \/>\n    QueryObject = extract(@&#8221;(?i)\\bfrom\\s+([^\\s]+)&#8221;, 1, tostring(RawEventData.QUERY_IDENTIFIER)), \/\/ Extract just the target object<br \/>\n    SalesforceUserId = tostring(RawEventData.USER_ID)<br \/>\n| where QueryText != &#8220;SOQL&#8221;<br \/>\n| project Timestamp, AccountDisplayName, SalesforceUserId, QueryObject, QueryText<\/p>\n<p class=\"wp-block-paragraph\">Hunt for users with very high Defender risk score signing into Salesforce<\/p>\n<p>let VeryRiskyUsers = IdentityInfo<br \/>\n| where DefenderRiskScoreNumber &gt;= 90<br \/>\n| distinct AccountObjectId<br \/>\nCloudAppEvents<br \/>\n| where Application == &#8220;Salesforce&#8221;<br \/>\n| where ActionType has &#8220;sso&#8221; or ActionType has &#8220;saml&#8221;<br \/>\n| where AccountObjectId in (VeryRiskyUsers)<br \/>\n| project Timestamp, AccountObjectId, AccountDisplayName, ActionType, UserAgent<br \/>\n| order by Timestamp desc<\/p>\n<p>Indicators of compromise (IOC)<\/p>\n<p>Indicator\u00a0\u00a0Type\u00a0\u00a0Description\u00a0\u00a0138.226.246.94\u00a0IP address\u00a0Used by the Klue integration to call Salesforce API to perform CRM queries\u00a0on June 11. Previously disclosed by Klue in their notification about the breach.212.86.125.24\u00a0IP address\u00a0213.111.148.90\u00a0IP address\u00a094.154.32.160\u00a0IP address\u00a0103.75.11.78IP addressUsed to target the Aura framework with guest access from June 19 to 22. These IP addresses were not previously published and were discovered by Microsoft as part of a novel campaign.103.75.11.110IP address<\/p>\n<p>MITRE ATT&amp;CK techniques observed<\/p>\n<p class=\"wp-block-paragraph\">Initial Access<\/p>\n<p>T1566.004 Phishing: Voice Phishing: Impersonating IT support to get victims to grant access.<\/p>\n<p>T1528 Steal Application Access Token: Using stolen OAuth tokens from Salesloft and Gainsight.<\/p>\n<p class=\"wp-block-paragraph\">Persistence<\/p>\n<p>T1671 Cloud Application Integration: Leveraging Connected Apps for access to a customer Salesforce environment.<\/p>\n<p class=\"wp-block-paragraph\">Collection<\/p>\n<p>T1213.004 Data from Information Repositories: Customer Relationship Management Software: Stealing data from a customer Salesforce environment.<\/p>\n<p class=\"wp-block-paragraph\">Exfiltration<\/p>\n<p>T1567 Exfiltration Over Web Service: Usage of the fake Data Loader application to steal data.<a id=\"_msocom_1\"\/><\/p>\n<p class=\"wp-block-paragraph\">This research is provided by Microsoft Defender Security Research, Shruti Ranjit,\u00a0Doug Cranston, Anand Deshpande, Ronen Rafaeli, and\u00a0with contributions from members of Microsoft Threat Intelligence.<\/p>\n<p>Learn more<\/p>\n<p class=\"wp-block-paragraph\" id=\"learn-more\">For the latest security research from the Microsoft Threat Intelligence community, check out the\u00a0<a href=\"https:\/\/aka.ms\/threatintelblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on\u00a0<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/x.com\/MsftSecIntel\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X (formerly Twitter)<\/a>, and\u00a0<a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the\u00a0<a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Review\u202four\u202fdocumentation\u202fto learn\u202fmore about our real-time protection capabilities and see how\u202fto\u202fenable them within your\u202forganization.\u202f\u202f\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"In this article In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity&hellip;\n","protected":false},"author":2,"featured_media":55892,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,320,7852,10646,24346,54285],"class_list":["post-104747","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-microsoft","tag-microsoft-copilot","tag-social-engineering","tag-supply-chain-attack","tag-vishing"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/104747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=104747"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/104747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/55892"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=104747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=104747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=104747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}