:

CITY-FORUM ATTACKS STEAL DATA FROM SALESFORCE, SERVICENOW

INDUSTRY DESK1 MIN READ
WED, AUG 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A data theft campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow customer portals to harvest sensitive information. The attackers use custom tools to access data exposed to anonymous users.

The "City-Forum" campaign targets publicly accessible portals where organizations inadvertently expose customer data through default or overly permissive access controls. The threat actors leverage custom tools to systematically extract information from these portals, taking advantage of weak authentication boundaries in cloud-based customer engagement platforms. Salesforce Experience Cloud and ServiceNow portals are common deployment targets for customer-facing applications, making them attractive vectors for mass exploitation. Organizations using these platforms frequently misconfigure permission settings, allowing anonymous or unauthenticated users to access restricted data. Security researchers attribute the campaign to City-Forum, a known data theft group. The ongoing nature of the attacks suggests widespread vulnerability in corporate configurations. Affected organizations should audit portal access controls, implement proper authentication requirements, and restrict data visibility based on user roles. Both Salesforce and ServiceNow recommend security reviews of portal configurations and access permissions.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.

2H AGOAI Desk

A new Android malware combo pairs NFC relay malware called WindRelay with the SpyNote remote administration tool to steal credit card data and conduct fraud in real time.

2H AGOSecurity Desk

Unknown actors are conducting widespread vulnerability scans while impersonating AI assistants like ClaudeBot, according to reports circulating in security communities.

3H AGOAI Desk

A critical vulnerability in Adobe Commerce and Magento platforms is being actively exploited to compromise customer accounts. The flaw, tracked as CVE-2026-71362, poses immediate risk to e-commerce operations worldwide.

3H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.