Feed›Data Breach›"City-Forum" data-theft attacks target Salesforce, ServiceNo...
Data BreachBleeping Computer
8.0 — CRITICAL

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

📅 12 August 2026 at 23:07 UTC📰 Bleeping ComputerView original source ↗
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

City-Forum is a data-theft campaign targeting Salesforce and ServiceNow portals, exploiting guest user access through overly permissive sharing rules and permissions.

⚙️Technical Details
Affected Systems
Salesforce Experience CloudServiceNow customer portals
Attack Vectors
/aura/s/sfsites/auraHostConfigController.getConfigDataSelectableListDataProviderController.getItems/webruntime/api/services/data/{version}/graphql/SiteRegister/CommunitiesSelfRegPOST /api/now/sp/search?sysparm_cancelable=true
💥Impact Assessment
Severity: high
Who Is at Risk
telecommunications companiesbanks and financial services firmsenterprise software vendorssecurity and data privacy companiespublic-sector portalsSeverity: high
🛡️Recommended Actions
1Review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings
2Disable the Experience Builder option that allows guest users to access public APIs when it is not required for LWR sites
3Review which search sources are exposed through Service Portals and ensure that sensitive data search sources use strict authentication and access controls
📦Affected Products
SalesforceServiceNow

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed