City-Forum Campaign Exploits Salesforce and ServiceNow Guest APIs to Harvest Data
A threat actor tracked as City-Forum is using a custom Go-based tool to silently enumerate publicly accessible data on Salesforce Experience Cloud and ServiceNow Service Portal instances without requiring authentication. The tool exploits misconfigured guest user permissions in Salesforce Aura and LWR GraphQL APIs to extract records including accounts, contacts, cases, leads, and documents left visible to unauthenticated users. It simultaneously probes ServiceNow's public Service Portal search API to collect data exposed through Knowledge Bases and custom search sources. All traffic originates from IP address 158.220.87.79 hosted on Contabo, linked to the domain city-forum.com since March 2025, with no malware deployed on victim systems and no user login events generated. Security researchers recommend disabling LWR guest UI APIs, enforcing minimum privilege for guest users, and adding login gates to ServiceNow search sources to mitigate the risk.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in