Product
medium
advisory
City Forum Campaign Scraping Salesforce and ServiceNow Portals
1 rule 1 TTP 1 IOCA persistent threat actor is utilizing a single VPS infrastructure to perform unauthorized data scraping from Salesforce and ServiceNow guest portals by exploiting over-privileged guest account permissions.
Salesforce Experience Cloud +1
1r
1t
1i
high
advisory
City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access
2 TTPs 2 IOCsAn unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.
Salesforce Aura +2
data-exfiltration
cloud-security
reconnaissance
guest-access-abuse
2t
2i