ShinyHunters Unleash City-Forum Campaign Against Salesforce and ServiceNow
A new wave of attacks has been launched against Salesforce and ServiceNow systems by an extortion group called ShinyHunters, according to researchers at Reco. The attackers have created their own toolset to carry out the attack through the UI-API layer, a previously unexploited vulnerability.
Reco has named this campaign 'City-Forum,' after a domain name associated with the attackers' IP address. Unlike previous attacks by ShinyHunters, which targeted dating sites and Oracle in January and June respectively, 'City-Forum' utilizes a unique approach to penetrate systems.
The threat is particularly noteworthy as the attackers have studied the services to map common data-leak vectors, indicating an advanced level of sophistication. Reco warns that organizations should be cautious about sharing login credentials with third parties.