A sophisticated attacker has been exploiting vulnerabilities in Salesforce and ServiceNow portals for over a year, targeting organizations that have accidentally left their guest accounts open to the public. This has allowed the attacker to harvest sensitive data from these companies.
Key Insights
The attacker utilized custom tools to specifically target over-permissioned guest accounts, taking advantage of the lack of security measures in place. The activity is not only ongoing but has been increasing in volume, with a staggering number of events logged from a single IP address, exceeding 560,000 instances.









