Breaking
Bursa Malaysia holds steady after Wall St rally, crude oil price tumbles - The StarMalaysia's Economy Stays Resilient Despite Global Uncertainty - Amir Hamzah - Portal Rasmi Kementerian KewanganPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55Bursa Malaysia holds steady after Wall St rally, crude oil price tumbles - The StarMalaysia's Economy Stays Resilient Despite Global Uncertainty - Amir Hamzah - Portal Rasmi Kementerian KewanganPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55
Economy

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

Source: BleepingComputer · August 13, 2026 at 7:45 AM · AI-assisted report

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Image: bleepingcomputer.com

KUALA LUMPUR, 13 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

**Data-Theft Campaign Targets Salesforce, ServiceNow Portals via Misconfigured Guest Access**

An ongoing data-theft campaign, codenamed *City-Forum* by SaaS security firm Reco, is exploiting misconfigured guest-user access in Salesforce Experience Cloud and ServiceNow customer portals to steal exposed data. The attacks, traced to a single server (IP: 158.220.87.79) hosted by German VPS provider Contabo, have targeted telecommunications firms, banks, enterprise software vendors, security companies, and public-sector portals globally. Activity remains ongoing, with Reco reporting a rising volume of incidents since March 2025.

The campaign does not exploit vulnerabilities in Salesforce or ServiceNow but instead targets data inadvertently exposed to unauthenticated guest users due to overly permissive sharing rules or portal configurations. Both platforms use guest accounts to manage unauthenticated visitors, and if these accounts are granted access to records, the data becomes retrievable via API endpoints.

On Salesforce, attackers primarily target the older Aura framework, sending requests to `/aura` or `/s/sfsites/aura` endpoints to identify publicly accessible objects such as Accounts, Contacts, and Cases. Reco observed one environment recording over 560,000 events from the attacker’s IP, nearly all related to guest Aura enumeration.

The attacker also exploits Salesforce’s newer Lightning Web Runtime (LWR) framework, using the UI API to send GraphQL requests to `/webruntime/api/services/data/{version}/graphql` to steal data exposed to guest accounts. Reco notes this technique has not been observed in public attack tools, distinguishing it from previous campaigns like ShinyHunters, which used modified versions of AuraInspector.

Additionally, the attacker probes Salesforce Experience Cloud sites via `/SiteRegister` and `/CommunitiesSelfReg` endpoints to check for self-registration capabilities, which could grant authenticated external accounts broader access.

For ServiceNow, the campaign abuses the native POST `/api/now/sp/search?sysparm_cancelable=true` endpoint, used for portal search functionality. If search sources are configured to allow guest access, attackers can enumerate exposed data by varying search terms. Reco highlights that ServiceNow transaction logs do not record POST body content, limiting defenders’ ability to determine the exact search terms used. The volume of requests in one investigated environment increased from tens to hundreds per day.

Reco has not found evidence linking the City-Forum campaign to ShinyHunters, noting that previous campaigns typically used multiple systems and IP addresses, whereas City-Forum’s infrastructure has remained on the same IP since March 2025. The firm advises Salesforce administrators to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings.

For LWR sites, disabling the Experience Builder option that allows guest access to public APIs is recommended to block enumeration endpoints. ServiceNow administrators should audit exposed search sources and enforce strict authentication for sensitive data access.

The campaign underscores the risks of misconfigured guest access in cloud platforms, with prevention effectiveness declining sharply once attackers gain valid credentials. Reco’s findings align with broader industry concerns about unauthorized data exposure in SaaS environments.

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.