A Sophisticated Campaign Targets Salesforce and ServiceNow with Custom Toolset
Researchers at Reco have uncovered a stealthy and innovative campaign that’s been targeting both Salesforce and ServiceNow using a custom-made multi-platform toolset. Dubbed “City-Forum”, this campaign has been exploiting vulnerabilities in both platforms, primarily focusing on unauthenticated guest user access.
The primary targets of the City-Forum campaign include telecoms, banks, financial-services firms, enterprise-software vendors (including security and data-privacy companies), and public-sector portals. This suggests that organizations handling sensitive customer or business data are at risk of being compromised.
The City-Forum toolset is designed to target both Salesforce Aura and its newer implementation, LWR (Lightweight Web Runtime). What’s striking about this campaign is its ability to integrate attacks on Aura with those on LWR in a single toolset. Furthermore, the researchers have observed that the same IP address has been used consistently since March 2025, scanning for vulnerabilities without rotating addresses.
The attackers are using the Guest User as their primary access key for both platforms. Every Salesforce Experience Cloud has its own Guest User, which can be accessed without authentication. Similarly, ServiceNow also has a similar guest user setup. The researchers warn that these guest users cannot be deleted, even if login is required, and their permissions and sharing rules remain intact.
This campaign’s use of a single machine reduces the attacker’s footprint, making it harder to detect for anomaly detection systems. However, this also makes it easier to block if known. The City-Forum toolset is designed to exfiltrate sensitive data from both Salesforce and ServiceNow platforms. In the case of Aura, the majority of the data collected and exfiltrated comes from unauthenticated guest user activities.
The researchers have noted that the attackers are using a custom multi-platform toolset, which sets it apart from other attacks targeting Aura, such as the ShinyHunters’ Salesforce Aura Campaign in March 2026. While Reco doesn’t rule out ShinyHunters being behind City-Forum, they emphasize that they don’t know who is responsible for this campaign.
Given the stealthy nature of this attack, organizations should be aware of their guest user settings and review them regularly. Misconfigured guest permissions can lead to unauthorized access to sensitive data. It’s also essential for administrators to monitor their systems closely, especially if they have enabled self-registration or have unauthenticated guest users.
Source: SecurityWeek — 2026-08-12