Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

0
Medium
News
Published: 08/12/2026 (08/12/2026, 13:00:00 UTC)
Source: SecurityWeek

Description

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 13:11:54 UTC

Technical Analysis

Researchers identified the City-Forum campaign exploiting unauthenticated guest user access on Salesforce Experience Cloud (Aura and LWR) and ServiceNow platforms. The attack uses a custom Go-based toolset to enumerate and exfiltrate data exposed to guest users without requiring authentication. The campaign targets sectors including telecom, finance, enterprise software, and public sector portals. It leverages the inherent existence of guest users in these platforms, which cannot be deleted and may have overly permissive read access. The ServiceNow attack focuses on a poorly documented search endpoint. The campaign is notable for its stealth, using a single IP address over an extended period to reduce detection risk. No evidence of platform breaches or authenticated user exploitation has been observed, but the potential for escalation exists if self-registration is enabled. The campaign differs from previous Aura-targeting attacks by integrating multi-platform targeting and a custom toolset.

Potential Impact

The campaign enables attackers to quietly enumerate and exfiltrate data that is publicly exposed to unauthenticated guest users on Salesforce and ServiceNow platforms. This can lead to significant data leakage from targeted organizations, including telecoms, financial services, enterprise software vendors, and public sector portals. Although no platform breaches or authenticated user exploits have been observed, the exposure of sensitive data due to misconfigured guest user permissions poses a serious confidentiality risk. The stealthy nature and high-volume but protocol-legitimate exfiltration make detection challenging.

Defensive Guidance

Organizations should immediately verify and restrict guest user permissions on Salesforce and ServiceNow platforms to ensure no sensitive data is exposed to unauthenticated users. Disable self-registration features in Salesforce Experience Cloud to prevent guest users from upgrading to authenticated users, which could increase data exposure. Review and tighten sharing rules, profiles, and code running in the context of guest users. Monitor for unusual enumeration activity and consider blocking known malicious IP addresses associated with the campaign. Follow vendor advisories and security best practices for these platforms to reduce exposure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/","fetched":true,"fetchedAt":"2026-08-12T13:11:14.475Z","wordCount":1491}

Threat ID: 6a7c70f2bf8831d539974f4f

Added to database: 08/12/2026, 13:11:14 UTC

Last enriched: 08/12/2026, 13:11:54 UTC

Last updated: 08/13/2026, 01:35:27 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses