A critical privilege escalation vulnerability called BodySnatcher was discovered in ServiceNow's Now Assist AI Agents and Virtual Agent API. The flaw allowed unauthenticated attackers to impersonate any user by knowing their email address, execute AI agent workflows with elevated privileges, and create backdoor admin accounts.

7m read timeFrom csoonline.com
Post cover image

Sort: