< ciso
brief />
Tag Banner

All news with #servicenow tag

23 articles

How AI and cybersecurity are reshaping ServiceNow

📰 ServiceNow faces major shifts as AI and cybersecurity converge, altering its traditional seat-based SaaS model. The company’s Armis acquisition and expansion into consumed services signal a pivot toward consumption pricing, infrastructure, and AI token usage. This strategy aims to defend its dominant position in large enterprises while responding to threats like seat compression and competition from cloud platforms. Buyers should watch for complex contracting and potential cost surprises.
read more →

Amazon Bedrock adds ServiceNow connector for knowledge

🔗 AWS introduces a ServiceNow data source connector for Amazon Bedrock Managed Knowledge Base, enabling direct ingestion of knowledge articles and service catalog items. The connector handles crawling, metadata extraction, file attachments, and incremental sync after you provide ServiceNow credentials. You can scope crawls by knowledge base, article category, or service catalog using sys ID inclusion lists to ingest only relevant content. This simplifies powering AI assistants and support agents with up-to-date ServiceNow institutional knowledge.
read more →

ServiceNow patches three maximum severity platform flaws

🔒 ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more →

ServiceNow issues high‑severity AI Platform security fixes

🔒 ServiceNow released patches on August 27, 2026, for four vulnerabilities affecting the ServiceNow AI Platform, three rated CVSS 10.0 and exploitable by unauthenticated attackers in certain conditions. The company deployed updates to hosted instances and provided fixes to partners and self‑hosted customers, who must apply them manually. ServiceNow stated it has no current evidence of exploitation and continues to support customers applying the patches.
read more →

ServiceNow patches three critical AI Platform flaws

🔒 ServiceNow issued emergency patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) can be exploited by unauthenticated attackers with low complexity and no user interaction. The company also patched a high-severity sandbox escape (CVE-2026-6876) and urged customers to update self-hosted instances promptly.
read more →

Weekly ThreatsDay: GhostJacking and New Attacks

📰 This ThreatsDay Bulletin aggregates a week of security updates across cloud services, AI agents, malware, data breaches, scams, and novel attack techniques. It summarizes campaigns like City-Forum targeting guest access in Salesforce and ServiceNow, the ShipMonk customer data exposure, and Cursor's pre-trust code execution flaw. The bulletin also highlights vishing platforms, AI agent hijacking (GhostJacking), defensive prompt-injection use, and other noteworthy incidents.
read more →

Critical ServiceNow RCE Flaw Now Observed Exploited

🛡️ Security researchers report active exploitation of a pre-auth sandbox escape and remote code execution bug (CVE-2026-6875) in the ServiceNow AI Platform. The vulnerability, disclosed in early April and patched for hosted and self-hosted instances in mid-July, allows unauthenticated actors to execute code by escaping the platform sandbox. Defused confirmed in-the-wild attacks days after patches were released, though ServiceNow states it is not currently aware of exploitation against instances and urges customers to apply updates immediately.
read more →

ServiceNow patches unauthenticated API exposure risk

🔒 ServiceNow notified customers after remediating a vulnerability that allowed an unauthenticated API endpoint to return tenant data under certain configurations. The issue, first reported via the vendor’s bug bounty program in April, prompted hosted updates on June 5 and guidance for self-hosted deployments. ServiceNow says affected instances were a subset of tenants and that observed activity appears linked to security researchers, though investigation continues. Customers are urged to apply updates and review logs for signs of unauthorized access.
read more →

ServiceNow flaw exploited to gain deeper access

🔒 ServiceNow disclosed a security incident after unidentified actors exploited a vulnerability to obtain unauthorized, deeper access to some customer instances. On June 5, 2026, the company applied a security update to hosted instances to restrict access to an endpoint so only authenticated users can reach it. ServiceNow detected anomalous activity and confirmed successful queries against instance tables for a subset of customers, who have been notified. The issue affects customers on the Australia platform release or those with specific pre-Australia configuration changes.
read more →

Palo Alto Networks and ServiceNow Integrate Prisma AIRS

🔒 The integration of Prisma AIRS with ServiceNow's AI Control Tower embeds AI runtime security and model governance directly into enterprise workflows. Prisma AIRS delivers real‑time detection and blocking of threats such as prompt injection and offensive outputs, while Model Security supplies risk profiles, red‑teaming results and vulnerability reports for third‑party and custom models. Together they provide centralized visibility, policy enforcement and safer AI adoption without disrupting user productivity.
read more →

Joint Vision: Simplified SASE Management at Scale Now

🔧 Palo Alto Networks, ServiceNow, and Bell Canada have built a ServiceNow application that automates the full lifecycle of Prisma SASE, creating a direct bridge between security operations and service management. The Prisma SASE app accelerates deployment from months to hours by automating Day 0–Day N tasks—provisioning, ZTNA connector setup, and mobile user workflows—while eliminating swivel-chair operations by syncing incidents into a single ServiceNow interface. ServiceNow’s Service Bridge enables cross-instance support for MSPs and the app supports direct CSP ticket creation, reducing MTTR and operational overhead.
read more →

January 2026 security roundup with Tony Anscombe — Lessons

🛡️ January brought several high-impact incidents that underline persistent enterprise risks. ServiceNow patched a critical AI-driven vulnerability (CVE-2025-12420) that could let unauthenticated actors impersonate admins on its AI platform. Unsecured Zendesk systems were abused for a large spam campaign, while the World Economic Forum reports cyber-fraud has overtaken ransomware as CEOs' top worry. Nike is also probing an alleged theft of 1.4 TB of data.
read more →

ServiceNow BodySnatcher Flaw Exposes AI Agent Risks

⚠️ Research firm AppOmni disclosed a critical privilege-escalation vulnerability called BodySnatcher in ServiceNow’s Now Assist AI Agents and Virtual Agent API that could let unauthenticated actors execute workflows as arbitrary users. ServiceNow says hosted instances were patched at the end of October and customers should upgrade to specified Now Assist and Virtual Agent API versions. AppOmni warns that default example agents and permissive authentication choices mean similar risky configurations could still exist in custom code or third-party integrations, and recommends enforcing MFA, reviewing agents, and applying the updates promptly.
read more →

ServiceNow Patches Critical Flaw in AI Platform — Oct 2025

🔒 ServiceNow has released fixes for a critical flaw in its ServiceNow AI Platform that could allow an unauthenticated actor to impersonate other users and perform arbitrary actions. Tracked as CVE-2025-12420 with a CVSS score of 9.3, the issue was addressed on October 30, 2025 and deployed to the majority of hosted instances. Patches were also shared with partners and self-hosted customers; administrators are advised to apply updates promptly to mitigate risk.
read more →

ServiceNow to Buy OT and IoT Security Firm Armis $7.8bn

🔒 ServiceNow will pay $7.8bn to acquire OT and IoT security specialist Armis, aiming to extend and enhance its security, risk and operational technology portfolios. The all-cash deal, expected to close in the second half of 2026, is positioned to more than triple ServiceNow’s security market opportunity. ServiceNow said Armis telemetry and asset insights will be integrated into its AI Control Tower to bolster AI governance and deliver automated remediation at scale. Executing on integration — notably tying Armis data into ServiceNow’s CMDB and workflows — is seen as the critical determinant of value realization.
read more →

ServiceNow’s $7.75B Armis Buy Signals Platform Shift

🔐 ServiceNow announced a $7.75 billion cash acquisition of cybersecurity vendor Armis, its largest deal to date, aiming to integrate device and asset visibility into its AI-driven workflow platform. Executives say the purchase will create an end-to-end security exposure and operations stack that ties discovery, governance, and remediation across IT, OT, IoT and edge. Analysts welcomed the move but warned it may push organizations from best-of-breed tools toward suite consolidation, and that full integration will take time.
read more →

ServiceNow in Talks to Acquire Identity Firm Veza

🔐 ServiceNow is reportedly in advanced talks to acquire identity-security startup Veza for more than $1 billion, a deal that could be announced next week. The move would pair ServiceNow's recent AI automation capabilities from Moveworks with Veza's Authorization Graph to map and govern permissions for human and machine identities. For customers, the acquisition aims to close trust and governance gaps around AI agents and non-human accounts, though integration, licensing, and standalone availability questions remain.
read more →

AWS Glue zero-ETL now supports CloudFormation & CDK

🚀 AWS Glue zero-ETL integrations now support AWS CloudFormation and the AWS Cloud Development Kit (CDK), enabling creation and management of zero-ETL integrations using infrastructure as code. This lets teams ingest data from DynamoDB and enterprise SaaS sources (Salesforce, ServiceNow, SAP, Zendesk) into Amazon Redshift, S3, and S3 Tables. CloudFormation and CDK support makes it easier to deploy, update, and version-control zero-ETL configurations consistently across multiple AWS accounts.
read more →

ServiceNow Now Assist agents vulnerable by default settings

🔒 AppOmni disclosed a second-order prompt injection that abuses ServiceNow's Now Assist agent discovery and agent-to-agent collaboration to perform unauthorized actions. A benign agent parsing attacker-crafted prompts can recruit other agents to read or modify records, exfiltrate data, or escalate privileges — all enabled by default configuration choices. AppOmni recommends supervised execution, disabling autonomous overrides, agent segmentation, and active monitoring to reduce risk.
read more →

Pentera Resolve Aims to Close the Remediation Gap Now

🔧 Pentera today unveiled Pentera Resolve, a platform extension that embeds automated remediation workflows into security validation to bridge the persistent remediation gap. The product converts validated findings into tracked, auditable tickets routed to owners in tools like ServiceNow, Jira, and Slack. Powered by AI-driven triage and contextual enrichment, it aims to replace manual consolidation with a measurable, repeatable remediation loop of validate, remediate, and re-test.
read more →