Security1 distinct publisher3 min readUpdated
Reco says one Contabo-hosted server has been pulling records from misconfigured Salesforce and ServiceNow guest portals for over a year. The indicator is a static IP and a default Go user agent.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
One server has been pulling records out of public-facing Salesforce and ServiceNow portals across multiple industries for more than a year, according to research published this week by the agent security firm Reco [1][19]. That reframes an exposure many teams closed out as a one-off Salesforce incident: what Reco describes is a persistent, cross-SaaS misconfiguration problem with an indicator defenders can search for today [18][11].
Reco calls the activity the City Forum campaign, after a domain tied to the attacker's IP [1]. The infrastructure is unglamorous: a single commodity VPS at 158.220.87.79, rented from the German provider Contabo [2]. Passive DNS puts the same domain on that address as far back as March 2025, and the server has not moved since [4]. Every request carries the default user agent of Go's net/http library, which tells Reco the client is a compiled, purpose-built program rather than anything driven from a browser [3]. Reco says targets so far include telecoms, banks and other financial services firms, enterprise software vendors including security and data privacy companies, and public sector portals, though it has not named individual organizations [5].
The volumes are not subtle. Most known abuse in this space leans on Salesforce's older Aura framework, sending high volumes of guest requests to enumerate objects and page through records [6]. This actor does that too, and Aura accounts for the bulk of the traffic Reco observed, with one target logging more than 560,000 events from that single IP [7]. What is new is the reach. The same tool queries Salesforce's newer Lightning Web Runtime sites through the UI-API, a data layer Reco says has no public write-ups or known scanning tools attached to it, stepping through API versions v56.0 to v66.0 in sequence [8] - eleven versions walked one after another [17]. It also hits a native ServiceNow Service Portal search endpoint, POST /api/now/sp/search, which similarly carries almost no public documentation [9].
The underlying fault is the same in both products. Salesforce Experience Cloud sites and ServiceNow portals both keep a persistent guest user that unauthenticated visitors execute as, and that identity cannot be deleted, only restricted [10]. If the guest profile can read a record, the record is public in practice, whether or not the browser experience asks for a login [20]. Reco's position is that the endpoints are working as designed, so remediation belongs at the profile, not the URL [13].
The checkable part is worth acting on before the attribution question resolves. On Salesforce, teams with Event Monitoring or Shield can pull AuraRequest and Sites log events and look for the Go-http-client user agent, the IP itself, and request paths containing /webruntime/api/services/data, alongside spikes in self-registration at /SiteRegister and /CommunitiesSelfReg [11]. On ServiceNow, the syslog_transaction table can be filtered by source IP and by URLs starting with /api/now/sp/search, with guest-created rows and unusual output length as the clearest sign of a live sweep [12]. Fixes follow: review guest sharing rules, strip unneeded object and field access from the guest profile, disable self-registration where it is not required, and turn off the Experience Builder setting that lets guests reach public APIs [14]. On ServiceNow, map which search sources are exposed to public portals and audit the Knowledge Base read criteria that decide what an anonymous query returns [15].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The activity traces back to one server, 158.220.87.79, hosted on a commodity VPS through the German provider Contabo.
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year.
Reco, an agent security platform, published research this week describing a campaign it named City Forum after a domain tied to the attacker's IP address.
Every request from that server carries the same fingerprint, the default user agent of Go's net/http library, which tells researchers the tool is a compiled, purpose-built program rather than anything run from a browser.
Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since.
Targets identified so far span telecoms, banks and other financial services firms, enterprise software vendors including security and data privacy companies, and public sector portals, though Reco has not named individual organizations.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor telemetry, no external corroboration
The technical detail is unusually concrete for a vendor report: a specific source IP, a reproducible user agent fingerprint, named log tables and request paths, an event count at one target, and a passive DNS timeline. That is checkable by any defender with the relevant logs. But every claim traces to one vendor's writeup relayed by one publisher in two duplicate items, with no named victims, no platform-vendor confirmation, no independent research, and no data behind the 'volume is climbing' assertion. The comparative claim about surface breadth versus prior campaigns has no supporting telemetry at all.
Real observed activity, undisclosed blast radius
There is measured real-world activity rather than a lab finding: sustained requests from one server across multiple industries for over a year, one target with 560,000-plus events, and infrastructure that Reco says is still live. What is missing is scope: no count of affected tenants, no named organizations, no confirmation of records actually exfiltrated, and no evidence about how many defenders have run the detections or applied the guest-profile hardening. That holds adoption below the midpoint despite the campaign being active.
Slightly overstated novelty over a known misconfiguration
The underlying failure mode is well-known over-permissioned guest access, and both abused endpoints are described as working as designed, yet the framing leans on novelty: a named campaign, undocumented data layers, and a stated contrast with ShinyHunters-attributed activity that no comparative evidence supports. The indicator itself is fragile, since a single IP and a default Go user agent are trivially changed. Against that, the detection and remediation detail is real and useful, so the gap is modest rather than large.
Vendor-named campaign with in-article commercial funnel
The sole primary source is a commercial security vendor that named the campaign itself, and the reporting is oriented toward the exposure class its product addresses. The article closes by directing security leaders to Reco's writeup and to Reco's AI security investment guide on sizing budget, evaluating vendors, and building a board business case, which is a direct commercial funnel. The single-publisher structure, with one article duplicated across two feed items, means no editorial counterweight to the vendor's framing.
Internally consistent but single-sourced
Confidence is moderate. The account is internally consistent, technically specific, and independently checkable by any org with Salesforce or ServiceNow logs, which supports the factual spine. It is nonetheless one vendor's telemetry carried by one publisher, with no victim confirmation, no platform response, and interpretive claims about novelty and rising volume that cannot be verified from the supplied material.
invest
ServiceNow paid $7.75bn for Armis and got a re-rating, not just a product line1 distinct publisher
build
Notion's agent stack is live, not slideware, and it only changes one of your decisions1 distinct publisher
build
A green build only proves your agent was consistent with itself1 distinct publisher
invest
Spark's $22M bet that the agent framework layer can stay independent1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 18, 2026