Overview
Security research firm Reco has tracked a fourteen-month campaign operationally named "City-Forum" targeting Salesforce Experience Cloud and ServiceNow Service Portals worldwide. The campaign leverages persistent guest user misconfigurations, operating from a single Contabo VPS at IP 158.220.87.79 with domain city-forum.com showing no IP rotation since March 2025.
This post provides a technical analysis of the attack vectors, detection methodologies, and remediation steps for affected organizations. The campaign primarily exploits over-permissioned guest accounts that were granted more access than required.
Attack Surface: Salesforce Experience Cloud
Aura Framework Enumeration
The threat actor's primary Salesforce attack leverages the older Aura framework through the /aura endpoint. By posting crafted descriptors, the actor enumerates all objects reachable from the guest context, then pages through records using SelectableListDataProviderController.getItems. One target logged over 560,000 events from the attacking IP during the campaign window.
Key indicators in Event Log Files:
- USER_AGENT containing Go-http-client/1.1
- CLIENT_IP matching 158.220.87.79
- ACTION_MESSAGE patterns like SelectableListDataProviderController/ACTION$getItems
Lightning Web Runtime (LWR) Exploitation
LWR represents Salesforce's newer framework, and its guest endpoints have become a blind spot. The attacker leverages two LWR surfaces:
- UI-API enumeration: Walking GraphQL versions from v56.0 through v66.0 against each experience site, leaving an unmistakable version-sweep pattern
- Self-registration probing: Appending /SiteRegister and /CommunitiesSelfReg to nearly every discovered site path
The /webruntime/ pattern is the piece nobody looks for today, making LWR an offensive blind spot that mainstream scanning tools like AuraInspector do not check.
Self-Registration as Amplification
When self-registration is enabled, a guest can promote itself to an authenticated external user, gaining access to significantly more data. This was observed across most Salesforce targets, making it a core not incidental component of the campaign.
Attack Surface: ServiceNow Service Portal
Hidden Search Endpoint
On ServiceNow, the attack concentrates on the native POST /api/now/sp/search?sysparm_cancelable=true endpoint. This endpoint has no published API reference and appears in no customization table, making it a hidden attack surface.
The attacker sends crafted POST requests with JSON bodies containing a query field, exploiting the ServiceNow Service Portal search functionality. Two search source types are relevant:
- Catalog (sc) sources: Require authentication a deliberate code change leaks data through this path
- Knowledge Base (kb) sources: No login check at all they go straight to KBPortalServiceImpl().getResultData(request), with access controlled only by per-KB Can Read user criteria, which are data configuration, not code-level gates
The trap for defenders: an unauthenticated POST returns HTTP 201 with an empty result set indistinguishable from no matches found, allowing attackers to sweep the endpoint with varying terms and learn what lies behind the walls by observing which queries return non-empty data.
Detection Methodologies
For Salesforce
Organizations with Event Monitoring Shield or the standalone add-on can hunt for this campaign by querying Event Log Files:
Key indicators:
- USER_AGENT containing Go-http-client/1.1
- CLIENT_IP matching 158.220.87.79
- ACTION_MESSAGE patterns like SelectableListDataProviderController/ACTION$getItems on Aura requests
- On Sites rows: any guest URI containing /webruntime/api/services/data/v the /webruntime/ pattern is the LWR tell
- A run of version calls climbing v56.0 to v57.0 to v58.0 indicates the operators version sweep
For ServiceNow
ServiceNow defenders can query the transaction log:
Filter: IP Address is 158.220.87.79 AND URL starts with /api/now/sp/search
Key indicators:
- Created by reads guest (legitimate user searches are attributed to their account, not guest, so guest traffic to this endpoint is already anomalous)
- Type is REST on /api/now/sp/search?sysparm_cancelable=true
- Volume climbing from tens to hundreds of requests per window
- Output length column: rows returning notably more than the empty-result baseline are searches that came back with content, and are the ones to run down first
Remediation Steps
Salesforce
- Audit guest sharing rules: Review object permissions and sharing rules for Guest User profiles. Prune unnecessary access.
- Disable LWR public APIs: If not needed, turn off Allow guest users to access public APIs in Experience Builder
- Monitor Event Log Files: Set up alerts for Go-http-client/1.1 user agent and the IP 158.220.87.79
- Restrict self-registration: Disable self-registration on Experience Cloud sites if not explicitly required
ServiceNow
- Review Knowledge Base access: Audit each KBS Can Read user criteria. Remove broad access if not needed.
- Catalog source hardening: Ensure catalog items have proper canViewOnSearch() gates this requires deliberate code changes
- Monitor transaction logs: Set alerts for guest traffic to /api/now/sp/search?sysparm_cancelable=true
- Implement IP blocking: Consider blocking the known attacker IP 158.220.87.79 at the firewall level
Conclusion
The City-Forum campaign underscores a fundamental principle granting anonymous users more access than they need creates persistent attack surfaces. The threat actor has not exploited a platform vulnerability they have exploited generous guest configurations across thousands of enterprise deployments.
Both Salesforce and ServiceNow provide the tools to audit and restrict guest access, but the onus is on site owners to review their configurations. With Event Monitoring on Salesforce and transaction log queries on ServiceNow, organizations can detect and hunt for this activity. The campaign has been active for seventeen months and shows no signs of stopping, making immediate remediation critical.
Sources
- Reco City-Forum Campaign analysis: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
- Google News RSS: data breach 2026 security
- Hacker News: Advanced threat targeting Salesforce and ServiceNow
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.