Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams should know.The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
Guest Access Data Theft
An ongoing campaign dubbed City-Forum has been observed targeting unauthenticated guest user access in both Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals. "A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025," Reco said. "Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools." The IP address in question is 158.220.87[.]79, which resolves to the domain "city-forum[.]com," giving the campaign its name. The use of little known techniques in the activity points to an advanced threat actor. Data is exfiltrated from Salesforce LWR sites using GraphQL. Targets include telecoms, banks and financial-services firms, enterprise-software vendors including security and data-privacy companies, and public-sector portals. Per Reco, the busiest target recorded more than 560,000 events from the attacker's IP address, with nearly all of them related to guest Aura enumeration.






