THE City-Forum campaign targets Salesforce and ServiceNow using a custom toolset aimed at telecoms, banks, and public-sector portals. Researchers note it's the first in-the-wild exploitation of Salesforce's UI-API guest surface. Attacks occur through unauthenticated guest users who have persistent access and can exploit misconfigured permissions. Key findings include a single IP address carrying out the attacks since March 2025 and a stealthy approach to data exfiltration that avoids detection.
The campaign is compared to previous attacks, highlighting its innovative methods. Reco emphasizes the importance of disabling self-registration features to prevent unauthorized user upgrades.