[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCgf54rxxP3IIFczUFSyBpMxbtQsH2hJ60iycMXmt0AM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"53a78168-8c33-44af-b724-71c733035077","city-forum-campaign-exploits-salesforce-servicenow-misconfigurations-to-steal-data","97f984f4-112c-4853-86a8-835f719a48bb","City-Forum Campaign Exploits Salesforce & ServiceNow Misconfigurations to Steal Data","The 'City-Forum' campaign demonstrates how misconfigured SaaS portals can expose sensitive organizational data to anonymous, unauthenticated users without any exploitation of software vulnerabilities. Attackers leveraged overly permissive access settings in Salesforce Experience Cloud and ServiceNow customer portals — configurations that organizations frequently overlook during deployment or after platform updates. This matters because SaaS platforms are often assumed to be 'secure by default,' leading teams to underinvest in reviewing access controls and permission models. The multi-sector targeting (finance, telecom, public sector) highlights that no industry is immune when foundational configuration hygiene is neglected. Novel techniques against newer Salesforce frameworks also suggest attackers are actively researching platform-specific misconfigurations faster than defenders are auditing them.","**Immediate actions:**\n- Audit all Salesforce Experience Cloud and ServiceNow portal configurations to ensure no data objects or endpoints are accessible to anonymous or guest users.\n- Revoke and review all public-facing API endpoints and guest-user profiles across SaaS platforms to enforce least-privilege access.\n\n**Long-term improvements:**\n- Establish a recurring SaaS configuration review process (at minimum quarterly) that includes permission models, guest access, and sharing rules after every major platform update.\n- Maintain an up-to-date inventory of all customer-facing portals and integrate them into your vulnerability management program with continuous posture monitoring.\n- Adopt a Zero Trust access model for all SaaS portals, requiring authenticated and authorized sessions before exposing any business data.\n\n**Detection measures:**\n- Deploy CASB (Cloud Access Security Broker) tooling to monitor and alert on anomalous data access patterns, particularly bulk record retrieval by unauthenticated or low-privilege users.\n- Enable and centralize audit logging for all Salesforce and ServiceNow portal activity, and create SIEM alerts for guest-user data access events.\n- Conduct regular third-party penetration tests targeting SaaS portal configurations, specifically focusing on unauthenticated access paths and newer platform frameworks.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 6 – Access Control Management","CIS Control 16 – Application Software Security","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 CM-6 (Configuration Settings)","NIST SP 800-53 CM-7 (Least Functionality)","NIST CSF PR.AC-3 (Remote Access Management)","NIST CSF PR.DS-5 (Protections Against Data Leaks)","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 32 – Security of Processing","ISO\u002FIEC 27001 A.9.4 (System and Application Access Control)","ISO\u002FIEC 27001 A.14.2 (Security in Development and Support Processes)","ITIL – Change Management (configuration drift review post-update)","published","2026-08-13T00:20:23.382401+00:00","2026-08-13T00:20:23.046+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcity-forum-data-theft-attacks-target-salesforce-servicenow-portals\u002F","city-forum-data-theft-attacks-target-salesforce-servicenow-portals-1d2292","\"City-Forum\" data-theft attacks target Salesforce, ServiceNow portals",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":41,"name":42,"slug":43,"description":44,"color":45},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":47,"name":48,"slug":49,"description":50,"color":51},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[53],{"id":54,"date":55,"edition":56,"title":57,"audio_url":58},"3e71b418-a7ec-4813-aca4-dad8cf676f44","2026-08-13","morning","ThreatNoir Morning Brief — August 13","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-13\u002Fthreatnoir-morning-brief-2026-08-13.mp3"]