New 'City-Forum' Attacks Exploit Guest Access in Salesforce and ServiceNow
Security researchers have identified a new attack campaign, dubbed 'City-Forum,' targeting two widely used business platforms: Salesforce and ServiceNow. The attackers are using a custom-built toolset to exploit unauthenticated guest access features on these platforms, allowing them to quietly enumerate and extract data without needing valid login credentials.
What makes this campaign particularly concerning is its stealthy nature. Rather than launching a loud, easily detected breach, the attackers appear to be methodically scanning for exposed data through guest access points that many organisations may not realise are publicly reachable. This approach can allow sensitive customer or business data to be siphoned off gradually, potentially going unnoticed for extended periods.
Many small and medium businesses rely on Salesforce and ServiceNow for customer relationship management and IT service operations, often without fully auditing how guest or public access is configured. If these settings are too permissive, businesses could be exposing internal records, customer details, or support ticket data to anyone who knows where to look, including automated tools built specifically to find and harvest this information.