[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwTbLGeMGekKDxKX58NBcg83YNaDzdKcwZS03k5Re240":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"19b84de5-ce33-4a86-9a43-30af47d3b02b","guest-user-abuse-fuels-stealthy-salesforce-servicenow-data-theft","6a05e841-6ec0-47f6-86f0-012675616083","Guest User Abuse Fuels Stealthy Salesforce & ServiceNow Data Theft","The 'City-Forum' campaign exploits a fundamental misconfiguration: unauthenticated guest user access left enabled on Salesforce and ServiceNow portals, granting attackers a low-friction entry point to enumerate and exfiltrate sensitive data. Both platforms support guest\u002Fpublic access modes intended for limited, controlled use, but when improperly scoped, these accounts become a silent backdoor requiring no credentials to abuse. The attackers' use of a single IP and domain over an extended period highlights a critical gap in anomaly detection and behavioral monitoring for SaaS platforms. This matters because SaaS misconfigurations are routinely overlooked in security programs that focus primarily on on-premises infrastructure, leaving critical business data exposed without any sign of a traditional breach.","**Immediate actions:**\n- Audit and disable unauthenticated guest user access on all Salesforce and ServiceNow instances unless explicitly required for a documented business purpose.\n- Review and restrict guest profile permissions to the absolute minimum scope, ensuring no access to sensitive objects, records, or APIs.\n\n**Long-term improvements:**\n- Establish a recurring SaaS configuration review process using tools like Salesforce Health Check and ServiceNow Security Center to detect permission drift.\n- Maintain an inventory of all public-facing SaaS portal endpoints and validate their authentication requirements on a quarterly basis.\n- Integrate SaaS platforms into your centralized SIEM to ensure API activity, guest access events, and data export actions are correlated and alerted upon.\n\n**Detection measures:**\n- Configure alerts for abnormal data enumeration patterns or bulk record access originating from guest or unauthenticated sessions.\n- Implement IP reputation monitoring and rate-limiting on public portal endpoints to flag single-source high-volume queries like those used in this campaign.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 5: Account Management","CIS Control 8: Audit Log Management","NIST AC-2: Account Management","NIST AC-3: Access Enforcement","NIST AC-17: Remote Access","NIST SI-4: System Monitoring","NIST CM-6: Configuration Settings","GDPR Article 25: Data Protection by Design and by Default","GDPR Article 32: Security of Processing","ITIL Service Configuration Management","published","2026-08-12T14:20:23.141357+00:00","2026-08-12T14:20:23.029+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fstealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset\u002F","stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset-4e350a","Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]