Skip to main content
Aggregate CSO Online 网络安全 15 Aug 2026 - 04:03

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

RSS 官方收录 · 可信分层展示

关键摘要

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.…

  • The attack appears similar to those perpetrated by the extortion group…
  • ShinyHunters has been particularly active this year, attacking dating …
  • Reco has named the latest campaign of attacks “City-Forum,” after a do…

摘要引擎:抽取

正文提要

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.

The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they could have found a new target.

Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools.

The threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach.

Regardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to.

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表