Vulnerabilità · 111 giorni fa
Una API di ServiceNow esposta trasforma i record di supporto in una rottura della fiducia, non solo in una fuga di dati. Se gli attacker hanno potuto interrogare le tabelle dell’istanza senza autenticazione, potrebbero aver estratto ticket, note e record interni che contengono password, API token e altri segreti che continuano a funzionare dopo che il portale è stato corretto.
5 fonti che coprono questa storia
Bug Bounty Research Triggers ServiceNow Security Alert
Bug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances.
ServiceNow tells customers a bug left some of their data exposed to the internet | TechCrunch
ServiceNow is used by thousands of enterprises to automate their internal processes, but says several customers had data accessed because of a security bug.
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
A ServiceNow security issue allowed unauthenticated users, in certain circumstances, to gain greater access to susceptible instances than intended.
ServiceNow Patches Vulnerability Exploited Against Some Customers
The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.
ServiceNow discloses security incident exposing customer data
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
Part of the PlainSec briefing for 2026-06-10