A sophisticated campaign, dubbed 'City-Forum' by SaaS security firm Reco, is actively targeting Salesforce Experience Cloud and ServiceNow customer portals. The campaign utilizes a custom multi-platform toolset to exploit guest user access, enabling the theft of data exposed to unauthenticated users.
The attacks are directed at both Salesforce Aura and the newer LWR implementations within Salesforce Experience Cloud, marking the first observed in-the-wild exploitation of Salesforce’s UI-API guest surface. ServiceNow platforms are also affected. Primary targets include telecommunications companies, banks, financial services firms, enterprise software vendors (including security and data-privacy companies), and public-sector portals globally.
The campaign leverages the inherent functionality of guest users in both Salesforce Experience Cloud and ServiceNow, which cannot be deleted. The custom toolset, noted for its ability to hit Salesforce over both Aura and LWR and also ServiceNow from the same server, is a Go binary. This indicates a tailored approach rather than the use of off-the-shelf tools.
All attacks have been traced to a single server with the IP address 158.220.87.79, hosted by German VPS provider Contabo. This IP address is associated with the city-forum.com domain, which has been active since at least March 2025. The attacks almost always use the default Go-http-client/1.1 user agent when downloading data.
The 'City-Forum' campaign highlights the risks associated with guest user configurations in widely used enterprise platforms. While not exploiting direct vulnerabilities in the platforms, the campaign capitalizes on overly permissive sharing rules to access sensitive information. The ongoing nature and increasing activity of these attacks underscore the importance of reviewing and securing guest user access settings.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An ongoing data theft campaign, dubbed "City-Forum," is exploiting misconfigured Salesforce Experience Cloud and ServiceNow customer portals to steal data exposed to unauthenticated guest users. This campaign affects various organizations globally, including banks and telecommunications firms, by leveraging overly permissive sharing rules rather than direct vulnerabilities in the platforms.
A new campaign named 'City-Forum' is exploiting guest user vulnerabilities in Salesforce Aura, Salesforce LWR, and ServiceNow platforms using a custom multi-platform toolset. This campaign targets telecommunications, banking, financial services, enterprise software vendors, and public-sector portals, leveraging guest user access to potentially read records without authentication.