Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial
    • Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night
    • Sparky Linux just restored 32-bit support – why that still matters
    • Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
    • Bitcoin Flashes Bottom Signals As “Digital Gold” Narrative Returns
    • A vest tested on the Artemis I mission blocked some radiation exposure
    • As DRC confronts largest Ebola outbreak, health agencies revise strategy
    • $13.2 billion gas project moves forward with ADNOC’s $8.2B EPC awards to Wison and Maire’s Tecnimont
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Reco is tracking a sophisticated and innovative campaign targeting both Salesforce and ServiceNow via what appears to be a custom made multi-platform toolset.

    Researchers believe the primary targets include telecoms, banks and financial-services firms, enterprise-software vendors (including security and data-privacy companies), and public-sector portals.

    The campaign has been named ‘City-Forum’. It is directed at both Salesforce Aura and the newer LWR implementations, where it is the first observed in‑the‑wild exploitation of Salesforce’s UI‑API guest surface. Furthermore, attacks on Aura (necessarily included in a Salesforce campaign since Aura users still outnumber LWR users) are integrated with the LWR attacks in a single toolset.

    “One Go binary hit Salesforce over both Aura and LWR and hit ServiceNow, from the same box,” comment the researchers in a blog report. This is consistent with a custom toolset rather than anything off the shelf like AuraInspector.

    The primary access key for both platforms is the Guest User. Every Salesforce Experience Cloud has its own Guest User in which an unauthenticated request works. ServiceNow is similar. “You cannot delete those guest users, and requiring login doesn’t remove them – the profile, its permissions, its sharing rules, and any code running in its context all still exist. If the guest can read a record, so can anyone on the internet.” 

    To better understand the degree of innovation in this campaign, it is useful to compare the City-Forum campaign with other attacks targeting Aura – especially the ShinyHunters’ Salesforce Aura Campaign disclosed in March 2026. As well as targeting LWR in Salesforce, “[City-Forum] hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools.”

    Advertisement. Scroll to continue reading.

    ShinyHunters targeted just Aura in Salesforce (no known targeting of ServiceNow) and used a modified version of the existing AuraInspector. City-Forum uses a new custom multi-platform toolset.

    Reco is at pains to explain that it doesn’t rule out ShinyHunters also being behind City-Forum, and goes on to add “We don’t know who this is, and we’re not ruling anyone in or out.”

    The City-Forum campaign uses a single machine. “The same IP has carried the same domain since March 2025 and is still scanning today – at least seventeen months on one address, with no rotation at any point.” That IP (158.220.87.79) resolves to city-forum.com.

    Reco draws no inference from this, but the main advantage of a single machine is that it reduces the attacker’s footprint to anomaly detection systems. It may be easier to block if known, but harder to detect if stealthy. 

    The campaign targets unauthenticated guest user access in both Salesforce and ServiceNow. However, conversion to an authenticated user in Salesforce would be possible if self-registration is enabled. There is no similar mechanism for ServiceNow. 

    Being an authenticated guest user is not necessary, but could provide access to more sensitive data. Since many organizations misconfigure guest permissions, this is a continuing possibility. However, “So far, we have only seen guest user activities – never an authenticated user, but we cannot rule it out,” comment the researchers.”

    Aura gives up the majority of the Salesforce data collected and exfiltrated. “The busiest target logged over 560,000 events… across the campaign window, essentially all of it guest Aura enumeration,” say the researchers. Data is also pulled from the Salesforce LWR sites using GraphQL.

    The ServiceNow attack targets the effectively undocumented search endpoint. It uses this to detect substantial content. “The Output length column is worth a glance while you’re here: rows returning noticeably more than the small empty-result baseline are searches that came back with content.” The attacker can pull from the most likely results.

    The exfiltration is not noisy – it is high volume but protocol-legitimate. This makes detection difficult, perhaps confirming the stealth intent behind using a single constant destination address.

    As with the ShinyHunters attack, there is no suggestion of a breach of the Salesforce or ServiceNow platforms.  “Every byte the attacker retrieved was something a site owner had exposed to anonymous users.”

    Being targeted by City-Forum is not a noisy easy-to-see attack. But most things can be found if you know where to look. The Reco research blog includes detailed IOCs and remediation instructions. At the very least, as soon as possible make sure that self-registration is not enabled. This will hinder any attempt for an unauthenticated guest to upgrade to an authenticated guest. 

    Related: BeyondTrust, LastPass Impacted by Klue-Salesforce Incident

    Related: Salesforce Instances Hacked via Gainsight Integrations

    Related: Extortion Group Leaks Millions of Records From Salesforce Hacks

    Related: Hackers Extorting Salesforce After Stealing Data From Dozens of Customers

    attacks CityForum custom Salesforce ServiceNow Stealthy Target Toolset
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

    Mindgard Raises $30 Million to Protect AI Systems

    SharePoint Vulnerability Exploited Shortly After PoC Release

    17 old software bugs that took way too long to squash

    The AI harness is the new attack surface

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.