Critical ServiceNow RCE flaws actively exploited to steal credentials
ID: 35dac767-8ccc-5742-b704-2badb3e96426
STIX ID: report--35dac767-8ccc-5742-b704-2badb3e96426
Feed Name: Bleeping Computer
Threat Score
Resecurity observed threat actors rapidly leveraging publicly available proofs-of-concept and scanners to chain critical ServiceNow flaws (notably CVE-2024-4879 plus CVE-2024-5178 and CVE-2024-5217) to gain RCE and full database access; attackers have dumped user lists and credentials from multiple victims across government, energy, and enterprise sectors despite ServiceNow releasing hotfixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
