City-Forum Reads Portal Data Through Guest Accounts

Reco says the City-Forum campaign has been pulling records from Salesforce Experience Cloud and ServiceNow portals for at least 17 months, with targets spanning telecom, finance, technology, and public-sector sites. The traffic comes from a single infrastructure point and uses a custom Go toolset rather than an off-the-shelf scanner. The method is simple: the attacker enters as the built-in guest user that every portal keeps, then asks for data the site was already configured to show that role. Because the guest account cannot be deleted and its permissions, sharing rules, and code context still exist, overexposure at that layer turns a public portal into a public read surface. That leaves a different kind of exposure than a normal software bug. If a customer or support portal grants guest users too much access, the data can be harvested quietly and repeatedly even when the platform itself is fully patched.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: City-Forum Reads Portal Data Through Guest Accounts

Sources