LIVE · cybersecurity feed
Live wire
breach

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

zeroday.news ·

An ongoing data theft campaign, dubbed "City-Forum" by the SaaS security firm Reco, is targeting data exposed to unauthenticated users through misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attacks, which are not exploiting vulnerabilities in either platform, have been traced to a single server and are reportedly increasing in volume.

Reco has observed the attacks originating from the IP address 158.220.87.79, hosted by the German VPS provider Contabo. This IP address has been associated with the domain city-forum.com since at least March 2025, suggesting a persistent infrastructure. The attackers consistently use the default "Go-http-client/1.1" user agent for data downloads.

The campaign targets a wide range of organizations globally, including telecommunications companies, banks, financial services firms, enterprise software vendors, security and data privacy companies, and public-sector entities. Reco emphasizes that all observed activity involves guest user accounts, though the possibility of authenticated user compromise is not ruled out.

The attacks leverage overly permissive sharing rules, permissions, or portal configurations that grant guest accounts access to data records. Both Salesforce Experience Cloud and ServiceNow utilize guest accounts for unauthenticated visitors. When these accounts are misconfigured, data can be retrieved via various API endpoints.

On Salesforce, the attackers primarily target the older Aura framework by sending requests to the `/aura` or `/s/sfsites/aura` endpoints. They first invoke `HostConfigController.getConfigData` to enumerate objects accessible to guest accounts, such as Accounts, Contacts, and Cases. Subsequently, `SelectableListDataProviderController.getItems` is used to retrieve records from these accessible objects. One heavily targeted environment recorded over 560,000 events from the attacker's IP, predominantly related to guest Aura enumeration.

While similar Salesforce guest-user abuse has been seen in past ShinyHunters campaigns, which used modified AuraInspector tools, the City-Forum attacker also targets Salesforce sites built with the newer Lightning Web Runtime (LWR) framework. For LWR sites, the attackers employ Salesforce's UI API to steal data exposed to guest accounts through GraphQL requests sent to `/webruntime/api/services/data/{version}/graphql`. Reco notes that this specific technique has not been observed in public attack tools like AuraInspector, S-RET, or CirrusGo.

The campaign also probes Salesforce Experience Cloud sites for `/SiteRegister` and `/CommunitiesSelfReg` endpoints to determine if self-registration is enabled. If active, this could allow a guest to create an authenticated external account with broader access privileges.

For ServiceNow Service Portals, the attacker targets the native `POST /api/now/sp/search?sysparm_cancelable=true` endpoint. This endpoint, used for portal search functionality, accepts anonymous requests and can return data if search sources are configured for guest access. Attackers vary search terms to enumerate exposed information, with one environment seeing search requests escalate from tens to hundreds daily. A challenge for defenders is that ServiceNow transaction logs do not record the POST body, preventing the exact search terms from being identified.

Despite similarities to previous ShinyHunters activity, Reco states there is no evidence linking the City-Forum campaign to that group. Previous campaigns typically utilized multiple systems and diverse IP addresses, whereas the City-Forum infrastructure has remained consistent on a single IP address since March 2025.

Salesforce administrators are advised to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings. For LWR sites, Reco recommends disabling the Experience Builder option that allows guest users to access public APIs when it is not essential, as this blocks access to API endpoints used for data enumeration and theft. ServiceNow administrators should review search sources exposed through Service Portals and ensure sensitive data search sources enforce strict authentication and access controls.

breachcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service