Executive Summary
In August 2026, multiple cybersecurity incidents emerged, including the 'City-Forum' campaign targeting unauthenticated guest user access in Salesforce Experience Cloud and ServiceNow Service Portals, leading to significant data exfiltration. Additionally, ShipMonk, a shipping provider for Trezor, suffered a data breach exposing sensitive customer information. Furthermore, Cursor's CLI coding agent was found to execute untrusted repository code without user consent, posing a significant security risk. These incidents underscore the evolving threat landscape, highlighting the need for robust security measures and vigilance against sophisticated attack vectors.
Why This Matters Now
The recent surge in sophisticated cyber attacks targeting widely-used platforms and services emphasizes the critical need for organizations to reassess and strengthen their security postures to protect sensitive data and maintain trust.
Attack Path Analysis
The attacker exploited unauthenticated guest user access in Salesforce Experience Cloud and ServiceNow Service Portals to extract sensitive data. By leveraging the UI-API and GraphQL, they escalated privileges to access and exfiltrate records. The attacker moved laterally across multiple organizations, targeting telecoms, banks, and public-sector portals. Command and control were maintained through a single server pulling records from the targeted platforms. Data exfiltration was achieved by extracting records from Salesforce LWR sites using GraphQL. The impact included unauthorized access to sensitive data, affecting multiple organizations and leading to potential data breaches.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker exploited unauthenticated guest user access in Salesforce Experience Cloud and ServiceNow Service Portals to extract sensitive data.
Related CVEs
CVE-2025-64109
CVSS 8.8A vulnerability in Cursor CLI Beta allows remote code execution via malicious MCP configuration files.
Affected Products:
Cursor Cursor CLI – < 2025.09.17-25b418f
Exploit Status:
proof of conceptCVE-2025-61592
CVSS 8.8Cursor CLI versions 1.7 and below allow remote code execution through permissive CLI configuration and prompt injection.
Affected Products:
Cursor Cursor CLI – <= 1.7
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Valid Accounts
Exploitation for Client Execution
Command and Scripting Interpreter
Event Triggered Execution
Hijack Execution Flow
Impair Defenses
Automated Exfiltration
Resource Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting Salesforce/ServiceNow expose customer data, payment systems vulnerable to AI agent hijacking, blockchain-based C2 infrastructure threatens transaction security.
Information Technology/IT
Developer environments compromised through Cursor CLI flaws, AI coding agents weaponized via malicious plugins, npm packages hijacked using Ethereum dead-drops for payload delivery.
Telecommunications
Major sector experiencing hyper-volumetric DDoS attacks exceeding 1Tbps, guest access exploitation in service portals, encrypted traffic vulnerabilities expose network infrastructure risks.
Health Care / Life Sciences
HIPAA compliance threatened by zero trust segmentation failures, encrypted traffic vulnerabilities expose patient data, ransomware targeting industrial healthcare systems increasing significantly.
Sources
- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Storieshttps://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.htmlVerified
- Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communicationhttps://github.com/cursor/cursor/security/advisories/GHSA-wj33-264c-j9cqVerified
- CVE-2025-64109: Cursor CLI Beta RCE Vulnerabilityhttps://www.sentinelone.com/vulnerability-database/cve-2025-64109/Verified
- Cursor CLI Untrusted Project RCEhttps://research.jfrog.com/vulnerabilities/cursor-cli-untrusted-project-rce/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit unauthenticated access, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit unauthenticated access points would likely be constrained, reducing the risk of initial data extraction.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through API exploitation would likely be constrained, reducing unauthorized access to sensitive records.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across organizations would likely be constrained, reducing the spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control through a centralized server would likely be constrained, reducing persistent unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data through GraphQL would likely be constrained, reducing unauthorized data leakage.
The overall impact of unauthorized data access and potential breaches would likely be constrained, reducing the scope of affected organizations.
Impact at a Glance
Affected Business Functions
- Software Development
- Code Review
- Continuous Integration
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of developer credentials and access tokens.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthenticated access and enforce least privilege policies.
- • Enhance East-West Traffic Security to monitor and control lateral movement within the network.
- • Deploy Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Conduct regular security assessments and audits to identify and remediate potential vulnerabilities in cloud platforms.



