Salesforce and ServiceNow attacks expose new API risks
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Salesforce and ServiceNow systems are under a new wave of attacks, with user data left exposed, according to researchers at Reco. The campaign, which the firm has dubbed “City-Forum,” appears to share similarities with the work of the extortion group ShinyHunters, but it also breaks new ground in how it breaks in.
A familiar foe, with a new twist
Reco’s researchers say the attack resembles those previously carried out by ShinyHunters, a group that has been unusually active this year. The group was tied to attacks on dating sites in January and on Oracle in June, and there are fears they may have turned their attention to enterprise software. But this time, the attacker took a different path, penetrating systems through the UI-API layer — an entry point that Reco says it had not previously seen used in such campaigns. The attacker also built its own custom toolset for the job, rather than relying on publicly available utilities.
Targeting an undocumented endpoint
A particularly notable aspect of the campaign is its focus on a native ServiceNow Service Portal search endpoint. According to Reco, this endpoint has almost no online documentation and few, if any, well-known open-source tools designed to interact with it. That suggests the attacker did significant reconnaissance and development work to find and exploit this specific weakness. Reco says the attacker studied the services to map out common data-leak vectors — a sign, the firm argues, of an advanced and methodical approach.
What’s at stake
Both Salesforce and ServiceNow are widely used by enterprises to manage customer relationships, IT services, and other critical business functions. A compromise of these systems could expose sensitive customer data, internal records, or other confidential information. Reco’s findings indicate that the attacker was able to access user data, though the full scope of the exposure is not yet clear.
Why credentials are the weak link
Regardless of who is behind the attack or how they pulled it off, Reco’s warning carries a clear message for organizations: be increasingly careful about who you give login credentials to. The campaign underscores that even well-defended platforms can be vulnerable if an attacker gains legitimate access through compromised or misused credentials.
The bigger picture
This incident fits into a broader pattern of rising extortion-driven attacks, with groups like ShinyHunters becoming more aggressive and innovative. The use of a custom toolset and an undocumented endpoint suggests that attackers are willing to invest heavily in finding novel ways into enterprise systems. For security teams, the lesson is to monitor not just for known attack patterns but also for signs of unusual activity in API traffic and user authentication logs.
What this means for you
If your organization relies on Salesforce or ServiceNow, it’s worth reviewing your security posture now. That includes auditing user accounts, enforcing multi-factor authentication, and watching for suspicious activity in API logs. Reco’s findings indicate that the attackers are not just spraying credentials at random but are targeting specific, high-value systems. Proactive monitoring and strict access controls could be the difference between a near-miss and a full-blown data breach.
Sources
- CSO Online Original source
Continue Reading
Akira exploits Safe Mode to bypass EDR defenses
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.
Mac screen sharing flaw is being exploited to mine crypto
A high-severity macOS bug is under attack, with hackers placing Monero miners via port 5900.
Security Roundup: Pentagon AI Deal Draws Fire
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.