'City-Forum' Campaign Exploits Unauthenticated Access for Data Heists
A sophisticated campaign dubbed 'City-Forum' has been targeting both Salesforce and ServiceNow using a custom-made multi-platform toolset. The researchers believe the primary targets include telecoms, banks, and financial-services firms, as well as enterprise-software vendors and public-sector portals.
The attackers are exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. This campaign has been observed in-the-wild and is considered a first for Salesforce's UI-API guest surface.
'One Go binary hit Salesforce over both Aura and LWR and hit ServiceNow, from the same box,' comment the researchers.