Security News

New 'City-Forum' Attacks Exploit Guest Access in Salesforce and ServiceNow

Security Week · 12 Aug 2026
Key Takeaway Review and restrict guest or unauthenticated access settings on platforms like Salesforce and ServiceNow to ensure no sensitive data is unintentionally exposed to the public.

Security researchers have identified a new attack campaign, dubbed 'City-Forum,' targeting two widely used business platforms: Salesforce and ServiceNow. The attackers are using a custom-built toolset to exploit unauthenticated guest access features on these platforms, allowing them to quietly enumerate and extract data without needing valid login credentials.

What makes this campaign particularly concerning is its stealthy nature. Rather than launching a loud, easily detected breach, the attackers appear to be methodically scanning for exposed data through guest access points that many organisations may not realise are publicly reachable. This approach can allow sensitive customer or business data to be siphoned off gradually, potentially going unnoticed for extended periods.

Many small and medium businesses rely on Salesforce and ServiceNow for customer relationship management and IT service operations, often without fully auditing how guest or public access is configured. If these settings are too permissive, businesses could be exposing internal records, customer details, or support ticket data to anyone who knows where to look, including automated tools built specifically to find and harvest this information.

Salesforce ServiceNow data exposure guest access SaaS security

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.