A stealthy attacker has been exploiting vulnerabilities in both Salesforce and ServiceNow portals, compromising sensitive data and creating backdoors for future attacks. The hacker’s activities have been ongoing since 2025, with a total of eleven identified instances of identity exposure used to unlock active attack paths.
The method behind the attacks is based on cross-domain privilege escalation, which involves exploiting vulnerabilities in multiple systems to gain elevated privileges and bypass security controls. In this case, the attacker has been targeting Salesforce and ServiceNow portals, which provide cloud-based services for customer relationship management (CRM) and IT service management (ITSM), respectively. These platforms are widely used by businesses and organizations worldwide.
The hacker’s primary goal is to expose sensitive identities, creating a vulnerability that can be exploited at a later stage. This allows the attacker to map cross-domain privilege escalation to key choke points in the system, effectively severing breach routes. By doing so, they create an active attack path that can be used to compromise additional systems and data.
The impact of these attacks is significant, as both Salesforce and ServiceNow are trusted platforms for many organizations. The compromised identities have been used to gain access to sensitive information, including customer data, financial records, and IT infrastructure details. Furthermore, the backdoors created by the attacker provide a permanent entry point into the system, allowing them to launch future attacks with relative ease.
The fact that these attacks have been ongoing since 2025 highlights a critical issue with many cloud-based services: inadequate security measures in place to prevent cross-domain privilege escalation. This vulnerability can be exploited using various techniques, including phishing, social engineering, and zero-day exploits. As such, organizations relying on these platforms must take immediate action to fortify their defenses.
To mitigate the risk of similar attacks, we recommend that businesses prioritize identity and access management (IAM) best practices, particularly in cloud-based environments. This includes implementing robust authentication protocols, segmenting sensitive data, and regularly reviewing user permissions and access controls. By doing so, organizations can significantly reduce the attack surface and prevent identity exposure from becoming a critical vulnerability.
In conclusion, the ongoing attacks on Salesforce and ServiceNow portals serve as a stark reminder of the importance of prioritizing cybersecurity in cloud-based services. As we continue to rely increasingly on these platforms for our operations, it is essential that we address the vulnerabilities associated with cross-domain privilege escalation and take proactive measures to prevent similar attacks from occurring in the future.
Source: The Hacker News — 2026-08-18