Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Venture Firm Team8 Secures Additional $365 Million

    August 13, 2026

    OpenAI’s “Head of Ethics” Suddenly Leaves Company Under Mysterious Circumstances

    August 13, 2026

    Twitch is using your streams to train Amazon’s AI, and you’re opted in by default

    August 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
    Cybersecurity

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    The Tech GuyBy The Tech GuyAugust 13, 2026No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Reco is tracking a sophisticated and innovative campaign targeting both Salesforce and ServiceNow via what appears to be a custom made multi-platform toolset.

    Advertisement

    Researchers believe the primary targets include telecoms, banks and financial-services firms, enterprise-software vendors (including security and data-privacy companies), and public-sector portals.

    The campaign has been named ‘City-Forum’. It is directed at both Salesforce Aura and the newer LWR implementations, where it is the first observed in‑the‑wild exploitation of Salesforce’s UI‑API guest surface. Furthermore, attacks on Aura (necessarily included in a Salesforce campaign since Aura users still outnumber LWR users) are integrated with the LWR attacks in a single toolset.

    “One Go binary hit Salesforce over both Aura and LWR and hit ServiceNow, from the same box,” comment the researchers in a blog report. This is consistent with a custom toolset rather than anything off the shelf like AuraInspector.

    The primary access key for both platforms is the Guest User. Every Salesforce Experience Cloud has its own Guest User in which an unauthenticated request works. ServiceNow is similar. “You cannot delete those guest users, and requiring login doesn’t remove them – the profile, its permissions, its sharing rules, and any code running in its context all still exist. If the guest can read a record, so can anyone on the internet.” 

    To better understand the degree of innovation in this campaign, it is useful to compare the City-Forum campaign with other attacks targeting Aura – especially the ShinyHunters’ Salesforce Aura Campaign disclosed in March 2026. As well as targeting LWR in Salesforce, “[City-Forum] hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools.”

    Advertisement. Scroll to continue reading.

    ShinyHunters targeted just Aura in Salesforce (no known targeting of ServiceNow) and used a modified version of the existing AuraInspector. City-Forum uses a new custom multi-platform toolset.

    Reco is at pains to explain that it doesn’t rule out ShinyHunters also being behind City-Forum, and goes on to add “We don’t know who this is, and we’re not ruling anyone in or out.”

    The City-Forum campaign uses a single machine. “The same IP has carried the same domain since March 2025 and is still scanning today – at least seventeen months on one address, with no rotation at any point.” That IP (158.220.87.79) resolves to city-forum.com.

    Reco draws no inference from this, but the main advantage of a single machine is that it reduces the attacker’s footprint to anomaly detection systems. It may be easier to block if known, but harder to detect if stealthy. 

    The campaign targets unauthenticated guest user access in both Salesforce and ServiceNow. However, conversion to an authenticated user in Salesforce would be possible if self-registration is enabled. There is no similar mechanism for ServiceNow. 

    Being an authenticated guest user is not necessary, but could provide access to more sensitive data. Since many organizations misconfigure guest permissions, this is a continuing possibility. However, “So far, we have only seen guest user activities – never an authenticated user, but we cannot rule it out,” comment the researchers.”

    Aura gives up the majority of the Salesforce data collected and exfiltrated. “The busiest target logged over 560,000 events… across the campaign window, essentially all of it guest Aura enumeration,” say the researchers. Data is also pulled from the Salesforce LWR sites using GraphQL.

    The ServiceNow attack targets the effectively undocumented search endpoint. It uses this to detect substantial content. “The Output length column is worth a glance while you’re here: rows returning noticeably more than the small empty-result baseline are searches that came back with content.” The attacker can pull from the most likely results.

    The exfiltration is not noisy – it is high volume but protocol-legitimate. This makes detection difficult, perhaps confirming the stealth intent behind using a single constant destination address.

    As with the ShinyHunters attack, there is no suggestion of a breach of the Salesforce or ServiceNow platforms.  “Every byte the attacker retrieved was something a site owner had exposed to anonymous users.”

    Being targeted by City-Forum is not a noisy easy-to-see attack. But most things can be found if you know where to look. The Reco research blog includes detailed IOCs and remediation instructions. At the very least, as soon as possible make sure that self-registration is not enabled. This will hinder any attempt for an unauthenticated guest to upgrade to an authenticated guest. 

    Related: BeyondTrust, LastPass Impacted by Klue-Salesforce Incident

    Related: Salesforce Instances Hacked via Gainsight Integrations

    Related: Extortion Group Leaks Millions of Records From Salesforce Hacks

    Related: Hackers Extorting Salesforce After Stealing Data From Dozens of Customers

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Venture Firm Team8 Secures Additional $365 Million

    August 13, 2026

    Mindgard Raises $30 Million to Protect AI Systems

    August 12, 2026

    SharePoint Vulnerability Exploited Shortly After PoC Release

    August 12, 2026

    Ceva Logistics Operations Disrupted by Cyberattack

    August 12, 2026

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    August 12, 2026

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    August 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Venture Firm Team8 Secures Additional $365 Million

    August 13, 2026

    OpenAI’s “Head of Ethics” Suddenly Leaves Company Under Mysterious Circumstances

    August 13, 2026

    Twitch is using your streams to train Amazon’s AI, and you’re opted in by default

    August 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.