B
今週中
SalesforceとServiceNowを標的とした「City-Forum」と呼ばれる高度な攻撃キャンペーン
📌 一言でいうと
SalesforceとServiceNowを標的とした「City-Forum」と呼ばれる高度な攻撃キャンペーンが確認されました。攻撃者はカスタムツールセットを使用し、特にSalesforceのUI-APIゲストサーフェスなどの認証不要なリクエストが可能な「ゲストユーザー」権限を悪用して侵入を試みます。主な標的は金融、通信、公共セクター、およびエンタープライズソフトウェアベンダーであると分析されています。
🔍該当判定
- Salesforceの『Experience Cloud』を利用して、外部向けサイトやポータルを公開している
- ServiceNowを利用して、外部ユーザーがアクセス可能なポータルサイトを運用している
- SalesforceのUI-APIやAura/LWRなどのフレームワークを用いて、ゲストユーザー(未認証ユーザー)が閲覧可能なページを作成している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Salesforce Experience CloudおよびServiceNowにおけるゲストユーザーの権限設定を最小限に制限し、不要なAPIアクセスや公開設定を無効化することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】SalesforceおよびServiceNowを標的とした攻撃キャンペーン「City-Forum」について
お疲れさまです。SalesforceおよびServiceNowを標的とした新キャンペーンに関する情報共有です。
■ 概要
「City-Forum」と呼ばれる攻撃者が、カスタムツールを用いてSalesforce(Aura/LWR)およびServiceNowのゲストユーザー権限を悪用し、認証なしでデータにアクセスしようとする攻撃が観測されています。特にSalesforceのUI-APIゲストサーフェスの悪用が確認されており、高度なツールセットが使用されています。
■ 影響範囲
- Salesforce Experience Cloud (Aura および LWR 実装)
- ServiceNow
■ 対応手順
1. SalesforceおよびServiceNowにおける「ゲストユーザー」の権限設定を確認し、必要最小限の権限に制限してください。
2. 公開設定(Guest User Profile)で不要なオブジェクトへのアクセス権やAPIアクセスが許可されていないかレビューしてください。
3. ゲストユーザーによる不審なAPIリクエストやアクセスログがないか監視を強化してください。
■ 参考情報
- Reco Security Blog
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。SalesforceおよびServiceNowを標的とした新キャンペーンに関する情報共有です。
■ 概要
「City-Forum」と呼ばれる攻撃者が、カスタムツールを用いてSalesforce(Aura/LWR)およびServiceNowのゲストユーザー権限を悪用し、認証なしでデータにアクセスしようとする攻撃が観測されています。特にSalesforceのUI-APIゲストサーフェスの悪用が確認されており、高度なツールセットが使用されています。
■ 影響範囲
- Salesforce Experience Cloud (Aura および LWR 実装)
- ServiceNow
■ 対応手順
1. SalesforceおよびServiceNowにおける「ゲストユーザー」の権限設定を確認し、必要最小限の権限に制限してください。
2. 公開設定(Guest User Profile)で不要なオブジェクトへのアクセス権やAPIアクセスが許可されていないかレビューしてください。
3. ゲストユーザーによる不審なAPIリクエストやアクセスログがないか監視を強化してください。
■ 参考情報
- Reco Security Blog
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Alert] 'City-Forum' Campaign Targeting Salesforce and ServiceNow
Dear IT/Security Team,
We are sharing information regarding a sophisticated campaign named 'City-Forum' targeting Salesforce and ServiceNow.
■ Overview
Attackers are using a custom multi-platform toolset to exploit 'Guest User' permissions. Notably, this is the first observed in-the-wild exploitation of Salesforce's UI-API guest surface across both Aura and LWR implementations, allowing unauthenticated requests to gain access.
■ Scope
- Salesforce Experience Cloud (Aura and LWR implementations)
- ServiceNow
■ Recommended Actions
1. Review and restrict 'Guest User' permissions in both Salesforce and ServiceNow to the absolute minimum required.
2. Audit Guest User Profiles to ensure no unnecessary object access or API permissions are enabled.
3. Enhance monitoring for anomalous API requests originating from guest accounts.
■ Reference
- Reco Security Blog
Priority: High
Deadline: Immediate review
Dear IT/Security Team,
We are sharing information regarding a sophisticated campaign named 'City-Forum' targeting Salesforce and ServiceNow.
■ Overview
Attackers are using a custom multi-platform toolset to exploit 'Guest User' permissions. Notably, this is the first observed in-the-wild exploitation of Salesforce's UI-API guest surface across both Aura and LWR implementations, allowing unauthenticated requests to gain access.
■ Scope
- Salesforce Experience Cloud (Aura and LWR implementations)
- ServiceNow
■ Recommended Actions
1. Review and restrict 'Guest User' permissions in both Salesforce and ServiceNow to the absolute minimum required.
2. Audit Guest User Profiles to ensure no unnecessary object access or API permissions are enabled.
3. Enhance monitoring for anomalous API requests originating from guest accounts.
■ Reference
- Reco Security Blog
Priority: High
Deadline: Immediate review