'Most Severe AI Vulnerability to Date' Hits ServiceNow
ID: e4541deb-e827-5e0a-845f-dd4faa155221
STIX ID: report--e4541deb-e827-5e0a-845f-dd4faa155221
Feed Name: Dark Reading
ServiceNow's Virtual Agent and Now Assist contained authentication weaknesses—a universal third‑party API credential and email-only identity verification—that allowed an attacker with minimal information to impersonate users and weaponize AI agents to create admin accounts, enabling full platform takeover and potentially broad lateral movement across integrated systems; AppOmni reported the issue and ServiceNow remediated it by rotating credentials and removing the exploited AI agent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
