Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
4 résultats taggé ServiceNow  ✕
Resurgence of In-The-Wild Activity Targeting Critical ServiceNow Vulnerabilities https://www.greynoise.io/blog/in-the-wild-activity-targeting-critical-servicenow-vulnerabilities
24/03/2025 09:22:41
QRCode
archive.org
thumbnail

GreyNoise has identified a notable resurgence of in-the-wild activity targeting three ServiceNow vulnerabilities CVE-2024-4879 (Critical), CVE-2024-5217 (Critical), and CVE-2024-5178 (Medium). These vulnerabilities reportedly may be chained together for full database access.

greynoise EN 2025 CVE-2024-5178 CVE-2024-4879 database access ServiceNow vulnerabilities
Enterprise ServiceNow Knowledge Bases at Risk https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/
20/09/2024 10:14:35
QRCode
archive.org
thumbnail

Read the blog to learn about ServiceNow’s Knowledge Base data exposure risks and how to mitigate these issues.

appomni EN 2024 ServiceNow dataleak Misconfiguration
Thousands of orgs at risk of ServiceNow KB data leaks https://www.theregister.com/2024/09/19/servicenow_knowledge_base_leaks/
20/09/2024 10:05:37
QRCode
archive.org
thumbnail

Security researchers say that thousands of companies are potentially leaking secrets from their internal knowledge base (KB) articles via ServiceNow misconfigurations.

Aaron Costello and Dan Meged, of the AppOmni and Adaptive Shield security shops respectively, separately published their findings this week, concluding that pages set to "private" could still be read by tinkering with a ServiceNow customer's KB widgets.

These widgets are essentially containers of information used to construct the pages in KB articles. These can include page elements that allow users to leave feedback on articles, either through star ratings or comments, for example.

theregister EN 2024 ServiceNow KB data-leak
Threat Actors Capitalize On ServiceNow Vulnerability https://cyble.com/blog/from-weaponization-to-victimization-fallout-from-the-servicenow-vulnerability/
06/08/2024 09:57:34
QRCode
archive.org
thumbnail

Cyble observes how Dark Web forums reveal ServiceNow users falling victim to a Remote Code Execution vulnerability, which exposes sensitive data & escalates risks across sectors.

cyble EN 2024 ServiceNow darkweb CVE-2024-4879 CVE-2024-5178 CVE-2024-5217
4460 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio