Over 1,000 ServiceNow instances found leaking corporate KB data
ID: 01b54d02-2381-5672-8c79-a0eafa724623
STIX ID: report--01b54d02-2381-5672-8c79-a0eafa724623
Feed Name: Bleeping Computer
AppOmni researchers discovered more than 1,000 misconfigured ServiceNow instances exposing Knowledge Base articles that contain sensitive corporate information — including PII, internal system details, and active credentials/tokens. They demonstrated a proof-of-concept using token interception, public widgets, and brute-forcing incremental KB IDs (KBXXXXXXX) to retrieve articles without authentication; ServiceNow has provided guidance and mitigation actions, but many KBs remain at risk due to reliance on User Criteria instead of ACLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
