One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.

The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces back to one server: 158.220.87.79, hosted on a

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week kept coming back to permission. A model crossed a boundary. A wallet trusted

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations,