onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Tech

Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems

Last updated: March 20, 2025 12:04 pm
OnlyTrustedInfo.com
Share
2 Min Read
Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems
SHARE

Hackers are ramping up their attempts to exploit a trio of year-old ServiceNow vulnerabilities to break into unpatched company instances, security researchers warned this week.

Threat intelligence startup GreyNoise said in a blog post on Tuesday that it had observed a “notable resurgence of in-the-wild activity” targeting the three ServiceNow vulnerabilities, tracked as CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217.

The vulnerabilities were first disclosed by researchers at Assetnote in May 2024 and patched by ServiceNow months later in July 2024. 

GreyNoise said that all three flaws have seen a resurgence in targeted exploitation attempts in the past week. It’s not known exactly who is behind this latest wave of targeting, but GreyNoise said that 70% of the malicious activity it observed in the past week targeted systems based in Israel, with activity also seen in Germany, Japan, and Lithuania. 

As first noted by Assetnote last year, GreyNoise also confirms that the vulnerabilities can be chained together for “full database access” of affected ServiceNow instances. Organizations often use the ServiceNow platform to host sensitive data about their employees, including their personally identifiable information and HR records related to their employment. 

ServiceNow spokesperson Erica Faltous told TechCrunch that the company first learned of the vulnerabilities “nearly a year ago”, and, “to date, we have not observed any customer impact from an attack campaign.”

Following Assetnote’s disclosure of the flaws last year, U.S. security firm Resecurity warned that foreign threat actors had attempted to exploit the three ServiceNow vulnerabilities to target both private sector companies and government agencies around the world. 

Resecurity said it saw targeted attempts at an energy company, a data center organization, a Middle Eastern government agency, and a software developer.

Cybersecurity company Imperva released another report in July 2024 warning that it had also observed exploitation attempts across 6,000 sites across various industries, with a focus on the financial services sector.

You Might Also Like

Southwest Airlines plane struck by lightning amid Memorial Day weekend storms

What Apple’s big win with its blood oxygen feature means for your watch

Astronomers get picture of aftermath of a star’s double detonation

How Michaela Benthaus’ Blue Origin Flight Shatters Space Accessibility Barriers

Trump and Xi’s Nvidia Blackwell Talks: Navigating the Future of Global AI Tech and Trade Controls

Share This Article
Facebook X Copy Link Print
Share
Previous Article Nike (NKE) Q3 2025 earnings Nike (NKE) Q3 2025 earnings
Next Article Onions! Bill Raftery’s guide to March Madness lingo Onions! Bill Raftery’s guide to March Madness lingo

Latest News

Victoire’s Ascent to PWHL Summit: 4-1 Win Over Torrent and the Poulin Injury Conundrum
Victoire’s Ascent to PWHL Summit: 4-1 Win Over Torrent and the Poulin Injury Conundrum
Sports March 20, 2026
DeBrincat’s Clutch Goal Propels Red Wings Past Canadiens in Crucial Atlantic Division Showdown
DeBrincat’s Clutch Goal Propels Red Wings Past Canadiens in Crucial Atlantic Division Showdown
Sports March 20, 2026
Indiana Anglers Can Now Hunt Invasive Carp 24/7 in Unprecedented Eradication Effort
Indiana Anglers Can Now Hunt Invasive Carp 24/7 in Unprecedented Eradication Effort
Sports March 20, 2026
March Madness Ignites: The Ten Players Who Made Thursday Unforgettable
March Madness Ignites: The Ten Players Who Made Thursday Unforgettable
Sports March 20, 2026
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2026 OnlyTrustedInfo.com . All Rights Reserved.