Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Posted on August 12, 2026 By CWS

Recent research by Reco has highlighted a sophisticated cyber attack campaign, dubbed ‘City-Forum’, targeting major platforms Salesforce and ServiceNow. This campaign employs a unique multi-platform toolset, raising concerns within the telecom, financial services, enterprise software, and public sector industries.

Targeted Platforms and Techniques

The ‘City-Forum’ campaign focuses on Salesforce’s Aura and LWR implementations, marking the first known in-the-wild exploitation of Salesforce’s UI-API guest interface. The attacks involve custom tools that simultaneously target both Salesforce and ServiceNow, indicating a high level of innovation and planning.

According to researchers, the attacks leverage the Guest User feature in Salesforce Experience Cloud and ServiceNow. These guest accounts allow unauthenticated requests, posing a significant risk as they cannot be deleted, and their permissions and sharing rules remain active. This vulnerability potentially exposes sensitive data if misconfigured.

Comparative Analysis with Previous Campaigns

In comparison to previous attacks, such as the ShinyHunters’ campaign in March 2026 which solely targeted Salesforce’s Aura, ‘City-Forum’ uses a novel custom multi-platform toolset. Unlike ShinyHunters, which modified existing tools, this campaign introduces entirely new methodologies, also affecting ServiceNow through an under-documented search endpoint.

Reco’s analysts speculate on the origin of these attacks but have not confirmed any links to ShinyHunters or other known groups. The persistent use of a single IP address since March 2025 suggests a strategic approach, minimizing the footprint to evade detection by anomaly systems.

Security Concerns and Recommendations

The ‘City-Forum’ attacks highlight the importance of securing guest user access. While current activities have not involved authenticated users, the possibility remains if self-registration is enabled. Organizations are advised to disable this feature as a precautionary measure.

Exfiltration of data from both Salesforce and ServiceNow is conducted in a stealthy manner, utilizing legitimate protocols. This reinforces the need for vigilant monitoring and robust security practices. Detailed indicators of compromise and remediation steps are available in the Reco research blog, providing guidance on mitigating these risks.

In conclusion, while no breaches of the core Salesforce or ServiceNow platforms have been reported, the exposure of data accessible to anonymous users underscores the critical need for comprehensive security measures. Organizations must remain alert to these sophisticated threats, ensuring configurations are tightened and access controls are rigorously enforced.

Security Week News Tags:Aura, City-Forum, cyber attacks, Cybersecurity, data privacy, enterprise software, financial services, LWR, public sector, Salesforce, Security, ServiceNow, ShinyHunters, Telecoms

Post navigation

Previous Post: Critical Cisco Flaw Exploited, Causes Remote DoS Risks
Next Post: 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape

Related Posts

Google Chrome 148 Update Fixes Critical Bugs Google Chrome 148 Update Fixes Critical Bugs Security Week News
Fortinet and Ivanti Address Critical Security Flaws Fortinet and Ivanti Address Critical Security Flaws Security Week News
GitHub’s NPM 12 Blocks Script Execution to Enhance Security GitHub’s NPM 12 Blocks Script Execution to Enhance Security Security Week News
Ransomware Gang Leaks Alleged Kettering Health Data Ransomware Gang Leaks Alleged Kettering Health Data Security Week News
US Deportation Airline GlobalX Confirms Hack US Deportation Airline GlobalX Confirms Hack Security Week News
Understanding AI: Challenges, Risks, and Future Solutions Understanding AI: Challenges, Risks, and Future Solutions Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape
  • Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks
  • Critical Cisco Flaw Exploited, Causes Remote DoS Risks
  • ShieldBreak: Critical Windows Defender Vulnerability Exposed
  • Cyberattack Disrupts Ceva Logistics in Europe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape
  • Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks
  • Critical Cisco Flaw Exploited, Causes Remote DoS Risks
  • ShieldBreak: Critical Windows Defender Vulnerability Exposed
  • Cyberattack Disrupts Ceva Logistics in Europe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark