Salesforce and ServiceNow portals have been actively scraped by a single attacker since 2025 according to Reco's research. That's over a year of undetected credential and customer data theft across multiple industries from one IP address. Meanwhile, TWINLOOT is embedding itself inside Microsoft Teams and SharePoint—the tools your teams trust daily—to move laterally through networks. And now we're seeing AI agents infected with self-propagating payloads through editable system prompts. What connects these three threats? They all exploit the gap between how we secure perimeter defenses and how we monitor trusted internal channels. In Latin America and the Caribbean, I've watched financial institutions get hit hardest because they assume Microsoft and Salesforce environments are inherently safe. They're not. You need visibility into what's actually happening inside your SaaS platforms, not just what's entering them. The City Forum campaign proves attackers don't need zero-days—they need patience and your complacency. Your team is probably still treating Salesforce access logs like a nice-to-have instead of a critical detective control. How are you currently monitoring lateral movement through your Microsoft 365 and Salesforce environments? #cybersecurity #fintech #infosec