ELSEIF
Your brief EB
334 stories from 97 feeds 287 clusters Refreshed 7 minutes ago next pull 18:36

SECURITY Signal 401

Custom toolset allegedly harvested data from misconfigured Salesforce and ServiceNow guest accounts for over a year

An unidentified attacker used bespoke tools to systematically extract data exposed by over-permissioned guest accounts on Salesforce and ServiceNow portals.

WHY IT MATTERS

This incident highlights the risks of misconfigured guest access in enterprise SaaS platforms. Engineers must audit permissions and monitor unauthenticated API activity to prevent similar data exposure.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The attacker targeted Salesforce LWR sites and ServiceNow portal search endpoints using undocumented techniques.

02

Over 560,000 enumeration attempts were logged on a single Salesforce target, indicating automated, large-scale harvesting.

03

Both platforms state the issue stems from customer misconfigurations, not vulnerabilities in their core systems.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Mystery attacker spent a year raiding Salesforce and ServiceNow portals Open ↗