| ~7 MIN READ |
|
This week's biggest story didn't involve a single line of malicious code. Someone just walked in the front door because nobody remembered to lock it, for a year and a half. This week the threats aren't zero-days, they're settings nobody double-checked: a guest account with too much access, a supply chain dependency nobody audited, a maintenance port left unlocked. Here's what slipped through.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
Data Exposure
🕵️ The Guest Account That Read Your CRM for 17 Months
Intro
No malware. No stolen password. No CVE. Just a guest account nobody remembered existed, and it worked for a year and a half.
What Happened
Researchers at Reco found a single attacker, operating from one rented German server since at least March 2025, quietly scraping Salesforce and ServiceNow customer portals worldwide. The technique, dubbed City-Forum, exploits the automatic "guest user" account both platforms create for unauthenticated visitors, an account that can't be deleted and often ships with far more access than it needs. Targets span telecoms, banks, enterprise software vendors, and public sector portals.
Why It Matters
There's no patch for this because there's no vulnerability, just a default configuration nobody audited, which means every org running these platforms should check its own guest permissions today, not wait on a vendor fix.
The Other Side
Reco hasn't attributed the campaign to a named group, and without confirmed data exfiltration at any single victim, it's hard to say yet how damaging 17 months of scraping actually was.
TL;DR: A mystery attacker has been silently scraping global Salesforce and ServiceNow data for 17 months by abusing an unaudited guest account.
Further reading: The Hacker News
|
|
Stop making AI decisions in the dark.
Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.
Harmonic Security Usage Explorer changes that.
You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.
You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.
CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.
|
|
|
Avoid Tax Season Scramble
Don’t wait until spring to scramble through deductions, documents, and expenses. BELAY’s experienced tax prep professionals can help you get organized before it turns into an emergency.
Download the free Personal Tax Prep Checklist to start today.
Strange but real
🎭 The Deepfake That Glitched at the Worst Possible Moment
Intro
A man spent months building an elaborate deepfake operation to steal other people's identities. He got caught because his face-swap software lagged for less than a second.
What Happened
Spanish police say the suspect made 38 attempts to fraudulently obtain digital certificates in other people's names, targeting a certificate-issuing security company, and succeeded more than once. His setup: forged ID documents, altered photos, a custom lighting rig to fake hologram security features, and real-time deepfake software to swap his face for his victims' during live video checks. Investigators say the software lagged during one call, and for under a second, his real face appeared instead of the mask.
Why It Matters
Live video identity verification is supposed to be the strong option, the fallback when a photo or ID scan alone isn't trustworthy enough. This case is a reminder that real-time deepfake tools are good enough to beat it, most of the time.
The Other Side
The system did eventually work: the verification company flagged the suspicious pattern of requests and reported it, which is what actually led to the arrest, not the software glitch alone.
TL;DR: A deepfake identity fraudster who spoofed 38 live video verification checks got caught when his face-swap software glitched for under a second.
Further reading: The Register
|
The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.



