業務プロセスの自動化プラットフォームServiceNowの「AI Platform」に存在する重大な脆弱性(CVE-2026-6875)について、公開された概念実証(PoC)とは異なる手法を用いた攻撃が進行していることが確認された。クラウド版は自動更新されているが、セルフホスト版を利用する組織は直ちに修正パッチを適用する必要がある。既知の攻撃手法をネットワーク層でブロックするだけでは防御として不十 ...
ServiceNow CVE-2026-6875, a critical unauthenticated RCE in the AI Platform, is under active exploitation. Threat intelligence firm Defused confirmed a second sandbox-escape gadget chain that bypasses ...