Security researchers have uncovered a significant vulnerability that has exposed Salesforce and ServiceNow portals to data leaks for an extended period. This zero-day exploit, associated with Metabase, has put enterprise tenants at risk of unauthorized access and data breaches. Over a span of 17 months, attackers exploited the vulnerability to bypass authentication, gaining access to sensitive information such as names, addresses, phone numbers, and login IP addresses, though financial data remained secure. The breach has prompted both Salesforce and ServiceNow to notify affected users, particularly in Europe, to address the potential impact on their systems.
N-able's N-central software has also been linked to a campaign named City-Forum, where a domain associated with the software was exploited using the CVE-2026-18577 vulnerability. The attackers maintained persistence in the system due to misconfigured portals, leading to unauthorized data access. In response, N-able has released a second security hotfix to mitigate ongoing attacks, aiming to secure its monitoring and management solution.
The discovery of this zero-day vulnerability has highlighted the increasing complexity of software supply chain risks. Dependabot, a tool used to monitor npm packages, has expanded its capabilities to include various ecosystems such as PyPI, Maven, RubyGems, and others. This expansion aims to detect threats across over 30 million repositories, emphasizing the need for robust security measures in software development.
A recent study by Quantus found that the vast majority of cloud environments suffer from misconfigurations, including unrotated keys and exposed services. The report underscores the necessity of automated inventory systems to track cryptographic assets, thereby reducing vulnerabilities in cloud infrastructure.
The breach has raised alarms about the security of critical infrastructure, especially as attackers continue to exploit such vulnerabilities to gain unauthorized access. Security teams are urged to review their systems, apply patches promptly, and conduct thorough audits to prevent similar incidents in the future.


