started · updated
City-Forum campaign targets Salesforce and ServiceNow guest portals
A data-theft campaign known as ‘City-Forum’ is targeting Salesforce and ServiceNow platforms by exploiting misconfigured guest access points. Security researchers at Reco have identified that the attackers use custom-developed tools to harvest records through unauthenticated guest-user permissions rather than traditional software vulnerabilities.
The campaign targets the UI-API layers of both services. In Salesforce, attackers interact with the Aura framework and the newer Lightning Web Runtime (LWR) implementation via GraphQL requests. In ServiceNow, the campaign targets a native search endpoint within the Service Portal. This allows attackers to map internal data structures and exfiltrate information through legitimate, albeit overly permissive, access configurations.
Targeted sectors include telecommunications, banking, financial services, software providers, and government portals. Researchers noted that the attack infrastructure has remained remarkably static, utilizing the same IP address and the city-forum.com domain for over 17 months without rotation. The activity highlights risks associated with SaaS configuration layers and the failure to strictly scope guest sharing rules.
Entities
City-Forum · Reco · Salesforce · ServiceNow