Salesforce and ServiceNow attacks expose new API risks
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
4 results for “api-security”
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
A missing authentication vulnerability in Spikster allows unauthenticated attackers to remotely access API routes and perform administrative actions.
A hard-coded JWT secret in self-hosted Clawvet API versions prior to 0.7.5 allows unauthenticated access to sensitive user information.
Threat actors are weaponizing years-old accounts to map organizational structures and probe sensitive repositories via the GitHub API.