Critical

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Help Net Security
Actively Exploited

Overview

For the past 17 months, an unknown individual has been accessing Salesforce and ServiceNow portals worldwide, according to researchers from Reco who are tracking this ongoing campaign dubbed 'City-Forum.' The campaign began using a domain that was registered back in 2002 but has since been linked to a generic server hosted in Germany. This unauthorized access has allowed the attacker to pull sensitive records from these widely used platforms, which could potentially compromise the data of numerous organizations. This situation raises serious concerns about the security measures in place for cloud-based services and highlights the need for companies to review their access controls and monitoring practices to protect against such long-term intrusions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Salesforce, ServiceNow
  • Action Required: Companies should review their access controls and monitoring practices for Salesforce and ServiceNow portals.
  • Timeline: Ongoing since 17 months

Original Article Summary

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world. The activity has not stopped, and there is more of it … More → The post A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months appeared first on Help Net Security.

Impact

Salesforce, ServiceNow

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since 17 months

Remediation

Companies should review their access controls and monitoring practices for Salesforce and ServiceNow portals.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Data Breach.

Related Coverage

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

Help Net Security

DDoS attacks have surged in scale during the first half of 2026, according to Cloudflare's latest report. Attackers are employing multi-vector techniques, leading to massive traffic floods that can exceed 1 terabit per second. These hyper-volumetric campaigns are impacting various online services across multiple industries, causing disruptions that can cripple businesses and services. The report notes that these attacks are not only larger but also shorter in duration, suggesting a shift towards more automated and efficient methods of conducting these attacks. As organizations increasingly rely on online services, the growing frequency and intensity of DDoS attacks present a significant challenge to cybersecurity.

Aug 13, 2026

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Help Net Security

Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.

Aug 13, 2026

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

BleepingComputer

A data theft campaign is targeting Salesforce Experience Cloud and ServiceNow customer portals, exploiting data that is exposed to anonymous users. Attackers are using custom tools to gain access to sensitive information, potentially impacting organizations that rely on these platforms. This ongoing threat raises concerns about the security of data shared on customer portals, particularly when access controls are not properly enforced. Companies using Salesforce and ServiceNow need to review their portal configurations and ensure that sensitive data is not accessible to unauthorized users. The situation highlights the importance of strong security measures and user authentication to protect against such attacks.

Aug 12, 2026

Thailand plans mandatory multi-factor authentication after massive data leak

SCM feed for Latest

Thailand's Digital Economy and Society Minister is pushing for mandatory multi-factor authentication (MFA) across all government systems. This move comes after a significant data leak, raising concerns about the security of sensitive information. By implementing MFA, the government aims to enhance protection against unauthorized access and potential cyber threats. The proposal is currently awaiting cabinet approval, highlighting the urgency of improving cybersecurity measures within government operations. This initiative is crucial, as it could set a precedent for better security practices in both public and private sectors in Thailand.

Aug 12, 2026

Colombia's Ministry of Justice hit by ransomware attack

SCM feed for Latest

Colombia's Ministry of Justice recently became the target of a ransomware attack that disrupted essential services, particularly those related to drug monitoring and legal procedures. This incident follows a warning from Colombia's national Computer Emergency Response Team (CERT), which had alerted agencies about an uptick in ransomware activity in the country. The attack raises significant concerns about the vulnerability of government systems to cyber threats, particularly as they handle sensitive information regarding drug-related crimes. The impact of this breach could delay legal processes and hinder the monitoring of illicit activities, potentially allowing criminal operations to flourish. As ransomware attacks continue to escalate globally, this incident serves as a stark reminder of the need for enhanced cybersecurity measures in critical government sectors.

Aug 12, 2026

LiteLLM supply chain attack impacted over 2,500 organizations

SCM feed for Latest

A recent supply chain attack targeting LiteLLM, a Python library and proxy server, has affected more than 2,500 organizations. The compromise occurred indirectly, meaning the attackers may have infiltrated the supply chain rather than attacking LiteLLM directly. This incident raises concerns about the security of third-party libraries and the potential ripple effects on organizations that rely on them for their operations. As LiteLLM is commonly used in various applications, the widespread nature of this attack puts many companies at risk, emphasizing the need for enhanced scrutiny of software dependencies. Organizations should assess their use of LiteLLM and consider implementing additional security measures to mitigate potential risks.

Aug 12, 2026