ServiceNow Discloses Security Incident Exposing Customer Data
ID: 5cae07a3-2ca2-551d-8d7d-35aae93f8a28
STIX ID: report--5cae07a3-2ca2-551d-8d7d-35aae93f8a28
Feed Name: HackRead
ServiceNow patched an unauthenticated API access issue (reported linked to `/api/now/related_list_edit/create`) on 5 June 2026 after observing successful queries against some customer instances; administrators reported suspicious requests potentially appearing as the Guest user and a notable IP indicator (51.159.98.241). The vendor has not confirmed exact data exfiltrated, and community posts allege earlier internal tracking and delayed prioritization, so affected customers should review logs, exposed records, rotate secrets, and verify Scripted REST resource authentication settings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
