A critical pre-authentication RCE in ServiceNow's AI Platform is being actively exploited. With 85% of Fortune 500 companies running ServiceNow and no credentials required to trigger the flaw, remediation speed is the only variable that matters.
A critical pre-authentication RCE in ServiceNow's AI Platform is being actively exploited. With 85% of Fortune 500 companies running ServiceNow and no credentials required to trigger the flaw, remediation speed is the only variable that matters.
Researchers from Seoul National University, UIUC, and Largosoft introduce Agent Data Injection (ADI) as a distinct attack class that bypasses existing IPI defenses with up to 50% success, targeting the structured metadata and context data agents implicitly trust.
Zenity Labs disclosed AgentForger on July 23, a ChatGPT Workspace Agents flaw that let a single crafted URL silently build and deploy an attacker-controlled AI agent with full access to an enterprise's connected apps — email, calendar, Slack, Teams, and more.
A malvertising campaign active July 21-22 used Bing ads and a malicious Claude artifact hosted on claude.ai itself to deliver SectopRAT to at least 29 organisations. The staging infrastructure exploited the corporate allow-listing of Anthropic's domain.
A server-side request forgery vulnerability in LMDeploy's vision-language image loader let attackers reach cloud instance metadata services and harvest full credentials. The first confirmed exploitation hit Sysdig's honeypot less than 13 hours after the CVE dropped.