Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .
AI Analysis
Technical Summary
Researchers identified the City-Forum campaign exploiting unauthenticated guest user access on Salesforce Experience Cloud (Aura and LWR) and ServiceNow platforms. The attack uses a custom Go-based toolset to enumerate and exfiltrate data exposed to guest users without requiring authentication. The campaign targets sectors including telecom, finance, enterprise software, and public sector portals. It leverages the inherent existence of guest users in these platforms, which cannot be deleted and may have overly permissive read access. The ServiceNow attack focuses on a poorly documented search endpoint. The campaign is notable for its stealth, using a single IP address over an extended period to reduce detection risk. No evidence of platform breaches or authenticated user exploitation has been observed, but the potential for escalation exists if self-registration is enabled. The campaign differs from previous Aura-targeting attacks by integrating multi-platform targeting and a custom toolset.
Potential Impact
The campaign enables attackers to quietly enumerate and exfiltrate data that is publicly exposed to unauthenticated guest users on Salesforce and ServiceNow platforms. This can lead to significant data leakage from targeted organizations, including telecoms, financial services, enterprise software vendors, and public sector portals. Although no platform breaches or authenticated user exploits have been observed, the exposure of sensitive data due to misconfigured guest user permissions poses a serious confidentiality risk. The stealthy nature and high-volume but protocol-legitimate exfiltration make detection challenging.
Mitigation Recommendations
Organizations should immediately verify and restrict guest user permissions on Salesforce and ServiceNow platforms to ensure no sensitive data is exposed to unauthenticated users. Disable self-registration features in Salesforce Experience Cloud to prevent guest users from upgrading to authenticated users, which could increase data exposure. Review and tighten sharing rules, profiles, and code running in the context of guest users. Monitor for unusual enumeration activity and consider blocking known malicious IP addresses associated with the campaign. Follow vendor advisories and security best practices for these platforms to reduce exposure.
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Description
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers identified the City-Forum campaign exploiting unauthenticated guest user access on Salesforce Experience Cloud (Aura and LWR) and ServiceNow platforms. The attack uses a custom Go-based toolset to enumerate and exfiltrate data exposed to guest users without requiring authentication. The campaign targets sectors including telecom, finance, enterprise software, and public sector portals. It leverages the inherent existence of guest users in these platforms, which cannot be deleted and may have overly permissive read access. The ServiceNow attack focuses on a poorly documented search endpoint. The campaign is notable for its stealth, using a single IP address over an extended period to reduce detection risk. No evidence of platform breaches or authenticated user exploitation has been observed, but the potential for escalation exists if self-registration is enabled. The campaign differs from previous Aura-targeting attacks by integrating multi-platform targeting and a custom toolset.
Potential Impact
The campaign enables attackers to quietly enumerate and exfiltrate data that is publicly exposed to unauthenticated guest users on Salesforce and ServiceNow platforms. This can lead to significant data leakage from targeted organizations, including telecoms, financial services, enterprise software vendors, and public sector portals. Although no platform breaches or authenticated user exploits have been observed, the exposure of sensitive data due to misconfigured guest user permissions poses a serious confidentiality risk. The stealthy nature and high-volume but protocol-legitimate exfiltration make detection challenging.
Defensive Guidance
Organizations should immediately verify and restrict guest user permissions on Salesforce and ServiceNow platforms to ensure no sensitive data is exposed to unauthenticated users. Disable self-registration features in Salesforce Experience Cloud to prevent guest users from upgrading to authenticated users, which could increase data exposure. Review and tighten sharing rules, profiles, and code running in the context of guest users. Monitor for unusual enumeration activity and consider blocking known malicious IP addresses associated with the campaign. Follow vendor advisories and security best practices for these platforms to reduce exposure.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/","fetched":true,"fetchedAt":"2026-08-12T13:11:14.475Z","wordCount":1491}
Threat ID: 6a7c70f2bf8831d539974f4f
Added to database: 08/12/2026, 13:11:14 UTC
Last enriched: 08/12/2026, 13:11:54 UTC
Last updated: 08/13/2026, 01:35:27 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.