Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #66August 16, 2026

Salesforce Portals Were Open for 17 Months

Someone quietly harvested records from Salesforce and ServiceNow portals worldwide for nearly a year and a half — without breaking a single thing. A new Linux botnet called Evooo1Bot is hijacking home routers and turning them into traffic-hiding relay points. Update your router's firmware today, and if you use GitHub, turn on Dependabot malware alerts now.

Breach of the Day

The Campaign That Went Unnoticed for 17 Months

Salesforce and ServiceNow are business software platforms used by thousands of companies to manage customer records, support tickets, and internal workflows. According to Help Net Security, researchers at security firm Reco uncovered a campaign — dubbed City-Forum — where an unknown party spent 17 months siphoning records from these portals worldwide.

What makes this story unusual is that nothing was broken into. The portals functioned exactly as designed. The attacker appeared to operate through a domain registered back in 2002, since abandoned, now pointing to a rented server in Germany. From there, someone was methodically pulling records out of corporate portals, one query at a time.

Think of it like a janitor who was never removed from the building's keycard system. No alarms, no broken locks — just access that should have been revoked long ago.

The same week, Framework — the company behind repairable, upgradeable laptops — confirmed attackers exploited a zero-day vulnerability (a flaw with no patch available at the time of attack) in Metabase, a business intelligence tool used to analyse data. Customer names, email addresses, phone numbers, physical addresses, and login IP addresses were accessed. Payment details were not.

What you should do: If you use Salesforce or ServiceNow at work, ask your IT team when user access was last audited. Old accounts with lingering access are a common and overlooked entry point.

Emerging Threats

Your Router May Already Be Someone Else's Spy Tunnel

A new botnet called Evooo1Bot is actively targeting home and small-office routers, according to Bleeping Computer. It is built on the leaked source code of Mirai — a well-known malware framework notorious for hijacking internet-connected devices at scale.

Once Evooo1Bot infects a device, it converts it into a SOCKS5 relay node (a proxy that secretly tunnels other people's internet traffic through your connection, hiding where that traffic really came from). Attackers can then route malicious activity through your router while you remain completely unaware.

The botnet also steals credentials, brute-forces SSH logins (automated password-guessing on remote access connections), and can launch DDoS attacks (coordinated floods of traffic designed to knock websites offline). Devices from NETGEAR, D-Link, Tenda, and others have been confirmed targets since at least July 2026.

What you should do: Log into your router's admin panel, update its firmware, and change the default admin password if you have not already.

Vulnerability Watch

No notable new vulnerability disclosed in the last 24 hours.

The Evooo1Bot botnet (covered in the AI & Emerging Threats section above) exploits a collection of previously known flaws across multiple device brands rather than a single newly disclosed CVE. No qualifying new CVE appears in today's brief.

Defender's Corner

Turn On GitHub Dependabot Malware Alerts — It Now Watches Eight Ecosystems

GitHub's Dependabot is a built-in tool that automatically scans your code's dependencies (the third-party packages your project relies on) and alerts you when something dangerous turns up.

Until this month, Dependabot's malware alerts only covered npm, one of the most popular package registries. That meant poisoned packages from PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer went undetected. As reported by Help Net Security, all eight ecosystems are now covered.

If you manage any GitHub repository, enable Dependabot malware alerts now. Go to your repository, click Settings → Security & analysis → Dependabot alerts, and switch it on. It is free, takes thirty seconds, and runs across more than 30 million repositories already.

Compliance Pulse

CISA Adds Cisco Firewall Flaw to Its Must-Patch List

CISA — the US Cybersecurity and Infrastructure Security Agency — has added CVE-2026-20349, a high-severity vulnerability in Cisco firewall software, to its Known Exploited Vulnerabilities catalog. The flaw is actively being used to temporarily knock Cisco firewalls offline. US civilian federal agencies were required to apply fixes by 14 August 2026. If your organisation runs Cisco firewalls and has not yet patched, treat this as urgent. Full details are available via Help Net Security.

Seventeen months of access, and the door was never even forced open — just never closed.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.