Data BreachBleeping Computer
8.0 — CRITICAL
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
City-Forum is a data-theft campaign targeting Salesforce and ServiceNow portals, exploiting guest user access through overly permissive sharing rules and permissions.
⚙️Technical Details
Affected Systems
Salesforce Experience CloudServiceNow customer portals
Attack Vectors
/aura/s/sfsites/auraHostConfigController.getConfigDataSelectableListDataProviderController.getItems/webruntime/api/services/data/{version}/graphql/SiteRegister/CommunitiesSelfRegPOST /api/now/sp/search?sysparm_cancelable=true
💥Impact Assessment
Severity: high
Who Is at Risk
telecommunications companiesbanks and financial services firmsenterprise software vendorssecurity and data privacy companiespublic-sector portalsSeverity: high
🛡️Recommended Actions
1Review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings
2Disable the Experience Builder option that allows guest users to access public APIs when it is not required for LWR sites
3Review which search sources are exposed through Service Portals and ensure that sensitive data search sources use strict authentication and access controls
📦Affected Products
SalesforceServiceNow
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
