Your Server Is Wide Open 🚨 And Your Salesforce Is Leaking
Two stories from today's security news deserve your attention: one is a critical server flaw that attackers are exploiting right now, and the other is a quiet campaign harvesting company data from Salesforce and ServiceNow without ever needing a password.
The VMware Flaw Attackers Are Already Inside
A critical vulnerability in VMware vCenter's Syslog Server is being actively exploited in the wild, according to forensics firm QUIRSO. The bug lets an attacker who has never logged in — no username, no password, no phishing required — run their own code on the server. Once in, attackers are installing a reverse SSH backdoor so they can quietly come and go long after the initial break-in.
Why this matters: vCenter is the control panel for a company's entire virtual server environment. Compromising it is less like stealing one laptop and more like walking off with the master key to the building. A patch exists, so the only question is whether your team has applied it — and whether anyone got there first.
'City-Forum' Is Quietly Vacuuming Up Your SaaS Data
Researchers at Reco uncovered a stealthy campaign, dubbed City-Forum, running a single custom-built tool against Salesforce and ServiceNow. The clever part: it doesn't break in at all. It simply asks these platforms for the data they'll hand over to anonymous "guest" users — a setting most companies enable without realizing how much it exposes. One target logged over 560,000 of these probing requests from a single IP address.
Why this matters: no alarm goes off, because technically nothing was hacked. If your business runs on Salesforce or ServiceNow, customer records and internal search results may be visible to anyone who knows where to look. This is a configuration problem, not a patching problem — which means it won't fix itself.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment