Critical

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

BleepingComputer
Actively Exploited

Overview

A data theft campaign is targeting Salesforce Experience Cloud and ServiceNow customer portals, exploiting data that is exposed to anonymous users. Attackers are using custom tools to gain access to sensitive information, potentially impacting organizations that rely on these platforms. This ongoing threat raises concerns about the security of data shared on customer portals, particularly when access controls are not properly enforced. Companies using Salesforce and ServiceNow need to review their portal configurations and ensure that sensitive data is not accessible to unauthorized users. The situation highlights the importance of strong security measures and user authentication to protect against such attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Salesforce Experience Cloud, ServiceNow customer portals
  • Action Required: Companies should review and tighten access controls on their customer portals to prevent unauthorized access to sensitive data.
  • Timeline: Ongoing since [timeframe]

Original Article Summary

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

Impact

Salesforce Experience Cloud, ServiceNow customer portals

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since [timeframe]

Remediation

Companies should review and tighten access controls on their customer portals to prevent unauthorized access to sensitive data.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Armored Likho expands its cyber-espionage toolkit

Securelist

Kaspersky researchers have identified a new cyber-espionage campaign linked to the group Armored Likho. This campaign masquerades as a fundraising initiative and uses a newly developed tool called the Still Toolkit, which is specifically designed to steal data from Telegram and eavesdrop on users. The implications of this attack are significant, particularly for individuals and organizations that rely on Telegram for communication. Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures to protect sensitive information. This incident illustrates the ongoing risks posed by sophisticated cyber-espionage tactics, which continue to evolve and target popular communication platforms.

Aug 13, 2026

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Help Net Security

Cisco has reported a high-severity vulnerability, designated as CVE-2026-20349, that attackers are using to cause temporary disruptions in the operation of Cisco firewalls. This flaw has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and is included in their catalog of known exploited vulnerabilities. US civilian federal agencies are required to address this issue by August 14, 2026. While Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in August, specific details regarding the attacks have not been disclosed. The urgency for remediation highlights the potential risks to organizations relying on Cisco’s firewall products.

Aug 13, 2026

Belgium's eID Authentication Opens Citizen Accounts to RCE

darkreading

Belgium's electronic ID system has suffered a significant breach due to serious vulnerabilities found in a crucial browser extension. This compromise means that unauthorized individuals could potentially access citizen accounts, revealing sensitive personal information. The issue raises concerns not just about Belgium's system but also highlights broader risks associated with browser extensions in general. As more services rely on digital identities, the security of these systems becomes increasingly important. Citizens using the eID system should be aware of the risks and consider additional security measures to protect their accounts.

Aug 13, 2026

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

Help Net Security

DDoS attacks have surged in scale during the first half of 2026, according to Cloudflare's latest report. Attackers are employing multi-vector techniques, leading to massive traffic floods that can exceed 1 terabit per second. These hyper-volumetric campaigns are impacting various online services across multiple industries, causing disruptions that can cripple businesses and services. The report notes that these attacks are not only larger but also shorter in duration, suggesting a shift towards more automated and efficient methods of conducting these attacks. As organizations increasingly rely on online services, the growing frequency and intensity of DDoS attacks present a significant challenge to cybersecurity.

Aug 13, 2026

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Help Net Security

Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.

Aug 13, 2026

Thailand plans mandatory multi-factor authentication after massive data leak

SCM feed for Latest

Thailand's Digital Economy and Society Minister is pushing for mandatory multi-factor authentication (MFA) across all government systems. This move comes after a significant data leak, raising concerns about the security of sensitive information. By implementing MFA, the government aims to enhance protection against unauthorized access and potential cyber threats. The proposal is currently awaiting cabinet approval, highlighting the urgency of improving cybersecurity measures within government operations. This initiative is crucial, as it could set a precedent for better security practices in both public and private sectors in Thailand.

Aug 12, 2026