August 29, 2026
- ServiceNow AI Platform patched four flaws, three of them CVSS 10.0 and reachable without authentication in certain configurations — code injection, SQL injection, and privilege escalation (BleepingComputer). Hosted instances were updated by the vendor; self-hosted operators carry the risk (The Hacker News).
· Vulnerabilities & Exploits
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 28, 2026
- SpecterOps published cleartext credential recovery against ServiceNow — a practical post-exploitation path from platform access to reusable secrets for downstream systems, which is exactly how ServiceNow tends to be positioned in an enterprise (SpecterOps).
· Exploitation & Vulnerabilities
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 13, 2026
- The "City-Forum" campaign is quietly exfiltrating data from Salesforce and ServiceNow by abusing unauthenticated guest access to enumerate and pull exposed records. Active since at least March 2025 across multiple sectors, it uses custom tooling, per Dark Reading and SecurityWeek.
· Threat Activity
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 8, 2026
- ShinyHunters is advertising 11.5M records from an unnamed victim spanning Salesforce, ServiceNow, and Entra, plus 3.1 TB+ of internal corporate data. @DarkWebInformer
· Data Breaches
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
July 21, 2026
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live