AUTO-UPDATED

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Global security researchers recently uncovered a 17-month data exposure affecting Salesforce and ServiceNow portals, while new zero-day exploits and supply chain attacks continue to threaten enterprise software environments.

Key Points

  • A long-running campaign dubbed City-Forum exploited Salesforce and ServiceNow portals for 17 months via a generic server.
  • Framework suffered a data breach after attackers leveraged a zero-day vulnerability in the Metabase business intelligence service.
  • A LiteLLM supply chain attack resulted in a 153GB archive of stolen credentials impacting major firms like AWS, Samsung, and Cisco.
  • Microsoft’s August 2026 Patch Tuesday addressed over 400 vulnerabilities, including one actively exploited zero-day (CVE-2026-68820).
  • Researchers identified 84 previously unknown security flaws in 5G network software, with 81 now assigned CVE tracking numbers.
  • GitHub expanded its Dependabot malware alerts to cover eight major package ecosystems, including PyPI, Maven, and Go.

Why it Matters

These incidents highlight the persistent vulnerability of widely used enterprise platforms and the increasing sophistication of supply chain attacks. Organizations must prioritize rapid patching and robust identity management to mitigate the risks posed by both automated exploits and long-term unauthorized data access.
Help Net Security Published by Help Net Security
Read original