news.mlab.sh
Back to the feed
threat-intel

Bug Bounty Research Triggers ServiceNow Security Alert

Low
Summary

ServiceNow experienced a situation where bug bounty research was mistakenly identified as a security breach targeting their customer instances. The issue involved unauthorized access to instance tables, but ServiceNow determined the activity stemmed from researchers submitting findings to their bug bounty program. The company addressed the issue with a security update and clarified the situation to customers.

ServiceNow’s customer instances were briefly flagged as being targeted by an unauthorized user who was able to query certain instance tables. This incident was initially triggered by bug bounty research conducted by external security researchers. ServiceNow quickly responded by applying a security update to hosted customer instances and notifying affected customers. The update focused on limiting access to authenticated users, specifically for customers on the Australia platform release or those with specific configuration changes on older releases.

Read the full article at Dark Reading