Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Single Attacker Targets Salesforce, ServiceNow Portals

Single Attacker Targets Salesforce, ServiceNow Portals

Posted on August 18, 2026 By CWS

In a concerning development for cloud security, a single infrastructure has been systematically extracting information from Salesforce and ServiceNow portals across various sectors for over a year. This revelation comes from Reco, an agent security platform, which disclosed these findings earlier this week.

Named the City Forum campaign, this operation traces its roots to a singular server with the IP address 158.220.87.79, hosted by Contabo in Germany. The operation utilizes the Go programming language’s net/http library, indicating a dedicated application, not a standard browser tool. This IP has been linked to the same domain since March 2025, and its targets include telecommunications, financial services, enterprise software vendors, and public sector portals.

Distinctive Characteristics of the Attack

Unlike previous Salesforce abuse cases, such as those by ShinyHunters, this campaign has a broader target range. Utilizing both Salesforce’s older Aura framework and the newer Lightning Web Runtime sites, the attacker manages to access API versions from v56.0 to v66.0. Similarly, the ServiceNow portal is accessed via the /api/now/sp/search endpoint, which lacks extensive public documentation.

The core issue, as outlined by Reco, is excessive access granted to guest identities on these platforms. Both Salesforce and ServiceNow portals maintain guest user profiles that, if not properly restricted, can expose sensitive data to unauthorized users.

Identifying and Mitigating the Threat

Reco provides detailed steps for detecting and mitigating these threats. For Salesforce, security teams should scrutinize AuraRequest and Sites log events, particularly looking for the Go-http-client user agent and specific request paths. On ServiceNow, the transaction logs should be analyzed for unusual activities from the source IP and anomalies in search request results.

Effective remediation involves tightening guest profile permissions rather than altering endpoint configurations. Salesforce administrators are advised to review guest sharing rules and limit unnecessary access, while ServiceNow users should audit public-facing portal configurations and knowledge base access criteria.

Current Status and Future Outlook

The infrastructure driving this campaign remains operational, and activity levels are reportedly increasing. Reco has not yet attributed this activity to any known group. Detailed technical insights, including request signatures and query samples, are available in Reco’s comprehensive report on the City Forum campaign.

For security leaders considering budget allocation for application exposure protection, Reco offers a framework that covers how to prioritize investments, evaluate suppliers, and justify expenditures to corporate boards.

To stay updated on similar topics, follow our publications on Google News, Twitter, and LinkedIn, where we share exclusive content and insights.

The Hacker News Tags:City Forum campaign, cloud security, Cyberattacks, data breach, Infrastructure, Reco, SaaS security, Salesforce, security measures, ServiceNow

Post navigation

Previous Post: Trojan Found in GEEKOM Realtek LAN Driver Package
Next Post: Webinar Explores AI’s Impact on Cybersecurity

Related Posts

Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play The Hacker News
3 Ways to Protect Your Business in 2026 3 Ways to Protect Your Business in 2026 The Hacker News
Understand Your Real Attack Surface in 45 Days Understand Your Real Attack Surface in 45 Days The Hacker News
Weekly Cybersecurity Recap: VMware, macOS, Windows Threats Weekly Cybersecurity Recap: VMware, macOS, Windows Threats The Hacker News
Smart TV Proxyware and AI in Cybercrime: Key Updates Smart TV Proxyware and AI in Cybercrime: Key Updates The Hacker News
3BB Network Breach: MeshCentral Backdoor Exploited 3BB Network Breach: MeshCentral Backdoor Exploited The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Session Cookie Flaw Risks Entra ID MFA Security
  • Sony Enhances PS5 Security Amid Relapse Jailbreak Concerns
  • Critical Dell CSM Vulnerabilities Allow Admin Access
  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Session Cookie Flaw Risks Entra ID MFA Security
  • Sony Enhances PS5 Security Amid Relapse Jailbreak Concerns
  • Critical Dell CSM Vulnerabilities Allow Admin Access
  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark