Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Cyber Campaign Targets Salesforce and ServiceNow

Global Cyber Campaign Targets Salesforce and ServiceNow

Posted on August 12, 2026 By CWS

A sophisticated cyber campaign has been identified, targeting Salesforce Experience Cloud and ServiceNow Service Portals on a global scale. Known as the ‘City-Forum Campaign’, this operation has been active since at least March 2025, affecting a wide range of industries, including telecommunications, financial services, and public sector organizations.

City-Forum Campaign Unveiled

The City-Forum Campaign, linked to a domain associated with the attackers, has been quietly extracting data from critical cloud platforms. Unlike other cybercrime entities such as ShinyHunters, this group has developed a more intricate technique that goes beyond exploiting Salesforce’s legacy Aura framework.

By leveraging both high-volume Aura enumeration and targeting Salesforce’s newer Lightning Web Runtime (LWR) sites, the attackers exploit a lack of public tools and documentation in the UI-API data layer. Simultaneously, they have identified an undocumented search endpoint within ServiceNow Service Portals, further broadening their attack surface.

Techniques and Indicators

Reco researchers point out that the attack reflects a well-planned strategy by operators who have extensively researched both Salesforce and ServiceNow platforms to identify potential data leakage points. The attacks originate from a single IP address, 158.220.87[.]79, hosted on a Contabo VPS in Germany.

Significant indicators of this operation include the use of a custom user-agent, Go-http-client/1.1, signifying an automated Go-based application. The attackers have maintained a static IP and domain presence, departing from the usual practice of using rotating proxies in such campaigns.

Impact and Defensive Measures

This campaign has managed to harvest enterprise information without resorting to traditional exploit payloads. The adversaries employ Google dorking techniques to map organizational perimeters before executing automated data extraction processes.

For Salesforce environments, it is crucial to review guest sharing rules and limit object and field-level permissions. Disabling self-registration and public API access within Experience Builder is recommended. In ServiceNow environments, auditing search sources and adjusting Knowledge Base access criteria can mitigate exposure.

Reco’s research emphasizes that the campaign exploits overly permissive configurations rather than zero-day vulnerabilities, urging organizations to reassess their security practices.

By understanding and addressing these vulnerabilities, companies can better secure their cloud infrastructure against sophisticated threats like the City-Forum Campaign.

Cyber Security News Tags:API vulnerabilities, cloud security, cyber attack, cyber threat, Cybersecurity, data security, Experience Cloud, IT security, LWR, Reco research, Salesforce, Service Portals, ServiceNow, tech news

Post navigation

Previous Post: Palo Alto Networks Addresses 11 Security Flaws in Latest Update
Next Post: Mindgard Secures $30 Million to Enhance AI Security

Related Posts

NadMesh Botnet Targets AI Systems Using Shodan NadMesh Botnet Targets AI Systems Using Shodan Cyber Security News
Fake Indian Tax Notice Distributes Dual Malware via Complex Chain Fake Indian Tax Notice Distributes Dual Malware via Complex Chain Cyber Security News
Google to Add New Layer of Developer Verification to Distribute Apps on Play Store Google to Add New Layer of Developer Verification to Distribute Apps on Play Store Cyber Security News
Malware Campaign Evades Detection with Advanced Techniques Malware Campaign Evades Detection with Advanced Techniques Cyber Security News
Jenkins Servers Exploited in DDoS Attacks on Valve Games Jenkins Servers Exploited in DDoS Attacks on Valve Games Cyber Security News
Microsoft to Phase Out Teams Together Mode for Better Performance Microsoft to Phase Out Teams Together Mode for Better Performance Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark