SECURITY Signal 401
Custom toolset allegedly harvested data from misconfigured Salesforce and ServiceNow guest accounts for over a year
An unidentified attacker used bespoke tools to systematically extract data exposed by over-permissioned guest accounts on Salesforce and ServiceNow portals.
This incident highlights the risks of misconfigured guest access in enterprise SaaS platforms. Engineers must audit permissions and monitor unauthenticated API activity to prevent similar data exposure.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The attacker targeted Salesforce LWR sites and ServiceNow portal search endpoints using undocumented techniques.
Over 560,000 enumeration attempts were logged on a single Salesforce target, indicating automated, large-scale harvesting.
Both platforms state the issue stems from customer misconfigurations, not vulnerabilities in their core systems.
THE CLUSTER