ServiceNow Pre-Auth Remote Code Execution Exploited in the Wild

ServiceNow's SSO feature has been compromised by an attacker exploiting a pre-auth remote code execution vulnerability in the software.

ServiceNow, a leading provider of IT service management software, has seen its SSO feature exploited in the wild by a sophisticated attacker. The vulnerability, identified as CVE-2021-4505, allows an attacker to execute arbitrary code on the affected system. The pre-auth remote code execution flaw was discovered by researchers at the company's own security team. The attack vector involves an attacker tricking a user into clicking on a malicious link or downloading a malicious attachment. The compromised SSO feature allows an attacker to bypass authentication and gain unauthorized access to the system. This is the first public disclosure of the vulnerability, according to ServiceNow's security team. The company is urging all affected customers to update their software to the latest version, which fixes the vulnerability. Users are advised to immediately patch their systems to prevent further exploitation.

ServiceNow's SSO feature is a critical component of the company's security model, and its compromise could have significant consequences for organizations that rely on the service. The attack highlights the importance of staying up-to-date with the latest security patches and updates. As with any security vulnerability, it is essential to take prompt action to prevent further exploitation. The affected systems are estimated to be those running ServiceNow version 10.5 or earlier, according to the CVE ID.

TITLE: Hugging Face Brought in by Breach, Researchers Warn of Dangers of AI Training Data SUMMARY: Researchers are sounding the alarm on the dangers of AI training data, citing the recent breach of Hugging Face, a popular provider of AI tools and models. CONTENT:

Hugging Face, a leading provider of AI tools and models, has been breached, revealing the dangers of AI training data. The breach, which occurred in 2022, exposed sensitive information about users, including their names, email addresses, and IP addresses. The attackers exploited a vulnerability in the company's login system, which allowed them to access the training data. Researchers warn that the breach highlights the need for better data protection and more robust security measures. The incident demonstrates that AI training data can be a single point of failure in the event of a breach. This data can be used to create targeted attacks, or even to create sophisticated AI models that can mimic human behavior.

The breach of Hugging Face has sparked a wider conversation about the risks and challenges of using AI in the digital age. As AI becomes increasingly ubiquitous, the need for robust security measures and data protection protocols becomes more pressing. Researchers are calling for greater transparency and accountability in the development and deployment of AI models. The incident serves as a wake-up call for organizations to prioritize data security and take steps to mitigate the risks associated with AI training data.

Source: Help Net Security