CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4322

As cited

Copy frozen at (site build).

threat intel

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers identified a campaign dubbed 'City-Forum' that exploits unauthenticated guest access on Salesforce and ServiceNow to enumerate and exfiltrate data. The attackers employ custom tooling to conduct these operations stealthily.

Why it matters: Organizations using Salesforce and ServiceNow must review guest access configurations and monitor for unauthorized data enumeration, as this campaign targets configurations that are difficult to detect.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers identified a campaign dubbed 'City-Forum' that exploits unauthenticated guest access on Salesforce and ServiceNow to enumerate and exfiltrate data. The attackers employ custom tooling to conduct these operations stealthily.

Why it matters: Organizations using Salesforce and ServiceNow must review guest access configurations and monitor for unauthorized data enumeration, as this campaign targets configurations that are difficult to detect.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers identified a campaign dubbed 'City-Forum' that exploits unauthenticated guest access on Salesforce and ServiceNow to enumerate and exfiltrate data. The attackers employ custom tooling to conduct these operations stealthily.

Why it matters: Organizations using Salesforce and ServiceNow must review guest access configurations and monitor for unauthorized data enumeration, as this campaign targets configurations that are difficult to detect.

VendorsSalesforceServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary