Security
Researchers link Salesforce and ServiceNow data sweeps to one active server
Reco researchers say one server has been extracting records from Salesforce and ServiceNow customer portals across multiple industries since at least March 2025. The firm says the activity uses Salesforce guest-access paths, including Aura and UI-API requests, as well as a ServiceNow portal-search endpoint. Reco attributes the exposure mechanism to guest identities granted excessive access and provides log signatures and remediation guidance. It says the infrastructure remains active and has not attributed the campaign to a named group.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
