{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/servicenow-service-portal/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Salesforce Aura","Salesforce LWR","ServiceNow Service Portal"],"_cs_severities":["high"],"_cs_tags":["data-exfiltration","cloud-security","reconnaissance","guest-access-abuse"],"_cs_type":"advisory","_cs_vendors":["Salesforce","ServiceNow"],"content_html":"\u003cp\u003eThe 'City-Forum' campaign is a sophisticated, stealthy operation targeting enterprise environments by abusing exposed Guest User access within Salesforce and ServiceNow. First reported in August 2026, the campaign employs a custom Go-based multi-platform toolset to enumerate data through Salesforce Aura, Salesforce LWR implementations (via GraphQL), and undocumented ServiceNow Service Portal search endpoints.\u003c/p\u003e\n\u003cp\u003eUnlike previous campaigns such as the one attributed to ShinyHunters, City-Forum is notable for its persistence and reliance on a single, long-standing IP address (158.220.87.79) that has remained active since March 2025. The attack focuses on protocol-legitimate traffic to minimize detection by traditional security tools. By exploiting the inherent permissions assigned to Guest Users, the actor systematically scrapes sensitive information that site owners have unintentionally exposed to anonymous users. The campaign primarily targets telecommunications, financial services, enterprise software vendors, and public-sector portals, with some instances logging over 560,000 enumeration events.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker conducts reconnaissance to identify Salesforce Aura/LWR instances and ServiceNow portals with publicly accessible guest endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with Salesforce Aura surfaces, utilizing the UI-API to enumerate records accessible to unauthenticated guest profiles.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with Salesforce LWR sites, leveraging GraphQL queries to extract structured data in an unauthenticated context.\u003c/li\u003e\n\u003cli\u003eAttacker targets undocumented ServiceNow search endpoints on the Service Portal, systematically iterating through queries.\u003c/li\u003e\n\u003cli\u003eAttacker monitors response sizes from the ServiceNow search endpoint to identify and filter queries that returned meaningful content versus baseline empty results.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates identified data through high-volume, protocol-legitimate requests directed to the static C2 infrastructure.\u003c/li\u003e\n\u003cli\u003eAttacker maintains persistent connectivity through a single IP address to evade detection systems relying on infrastructure rotation or domain flux.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign results in unauthorized exposure and exfiltration of sensitive information, including customer records, financial data, and proprietary enterprise details. The impact is primarily driven by the misconfiguration of guest user sharing rules and permissions, allowing anonymous internet access to sensitive records. While no direct breach of the Salesforce or ServiceNow platforms themselves has been observed, thousands of individual customer instances are potentially exposed, with some targets experiencing over half a million unauthorized data retrieval events.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit and restrict Guest User permissions in Salesforce Experience Cloud, ensuring no sensitive data is exposed to unauthenticated anonymous users.\u003c/li\u003e\n\u003cli\u003eDisable 'self-registration' features in Salesforce instances to prevent Guest Users from upgrading their privileges to authenticated user sessions.\u003c/li\u003e\n\u003cli\u003eReview ServiceNow Service Portal search configurations and apply appropriate ACLs to ensure undocumented search endpoints are not accessible to public guest users.\u003c/li\u003e\n\u003cli\u003eBlock the IP address 158.220.87.79 and the domain city-forum.com at the network perimeter, as these have been associated with long-term scanning and data retrieval.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unusually high volumes of search queries or UI-API/GraphQL requests originating from unauthenticated sessions in your Salesforce and ServiceNow environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T13:47:13Z","date_published":"2026-08-12T13:47:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-city-forum-attacks/","summary":"An unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.","title":"City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access","url":"https://feed.craftedsignal.io/briefs/2026-08-city-forum-attacks/"}],"language":"en","title":"CraftedSignal Threat Feed - ServiceNow Service Portal","version":"https://jsonfeed.org/version/1.1"}