Overview
- Reco published its findings on Wednesday, August 12, 2026, saying the campaign is active and climbing in volume and that the same infrastructure has run since at least March 2025.
- All attacks trace to one Contabo-hosted IP (158.220.87.79) resolving to city-forum.com and use a custom Go binary that targets Salesforce Aura, the newer LWR GraphQL UI API, and ServiceNow portal search endpoints.
- The attacker abuses misconfigured Guest User access rather than platform flaws so any record, file, or search source left readable to anonymous users can be enumerated and downloaded.
- Exfiltration is high-volume but protocol-legitimate, which produced large event counts on victims yet left few obvious anomalies in logs and made it hard to see exact ServiceNow search terms.
- Reco published IOCs and clear fixes for defenders, including auditing guest sharing rules and permissions, disabling unnecessary guest API access for LWR, turning off self-registration if not needed, and restricting ServiceNow search sources to authenticated contexts.