ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts

The Hacker News

Overview

Malicious actors can exploit vulnerabilities in ServiceNow's Now Assist AI platform through second-order prompt injection attacks, allowing unauthorized actions and potential data exfiltration. This issue highlights significant security risks associated with default configurations in generative AI systems.

Key Takeaways

  • Affected Systems: ServiceNow's Now Assist generative artificial intelligence platform
  • Action Required: Review and adjust default configurations in ServiceNow's Now Assist to prevent prompt injection attacks.
  • Timeline: Newly disclosed

Original Article Summary

Malicious actors can exploit default configurations in ServiceNow's Now Assist generative artificial intelligence (AI) platform and leverage its agentic capabilities to conduct prompt injection attacks. The second-order prompt injection, according to AppOmni, makes use of Now Assist's agent-to-agent discovery to execute unauthorized actions, enabling attackers to copy and exfiltrate sensitive

Impact

ServiceNow's Now Assist generative artificial intelligence platform

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Review and adjust default configurations in ServiceNow's Now Assist to prevent prompt injection attacks. Implement security best practices for generative AI systems.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit.

Related Coverage

CodeBuild Flaw Put AWS Console Supply Chain At Risk

Infosecurity Magazine

A misconfiguration in AWS CodeBuild has left key repositories vulnerable to potential attacks. This flaw could allow unauthorized access to sensitive data stored within those repositories, posing a significant risk to companies relying on AWS for their software development and deployment processes. Developers and organizations using AWS CodeBuild should be aware of this vulnerability and take immediate action to secure their environments. The issue emphasizes the need for stringent security practices, especially in cloud-based development tools. As this misconfiguration could impact a wide range of users, timely remediation is essential to prevent exploitation.

Jan 15, 2026

Cyber Threat Actors Ramp Up Attacks on Industrial Environments

Infosecurity Magazine

A recent report from Cyble reveals that hacktivists and cybercriminals are increasingly targeting industrial systems, looking to exploit vulnerabilities within these environments. This uptick in attacks poses significant risks to companies operating in sectors such as manufacturing, energy, and utilities, potentially leading to disruptions in operations and financial losses. The report emphasizes the critical need for these organizations to enhance their cybersecurity measures and patch known vulnerabilities to safeguard their systems. As attackers become more sophisticated, the potential for severe consequences, including data breaches and operational downtime, grows. Companies must prioritize security protocols to protect their infrastructure from these escalating threats.

Jan 15, 2026

Your Windows PC needs this patch to ward off nasty bootkit malware - update now

Latest news

The January Patch Tuesday updates for Windows include important changes to Secure Boot, which safeguards computers against bootkit malware. Secure Boot is a security feature that ensures only trusted software is loaded during the startup process. The updates address expiring certificates that could compromise this protection if not renewed. Users and IT administrators are urged to install these patches promptly to mitigate the risk of bootkit attacks, which can allow malicious software to take control of a system before the operating system loads. Keeping Secure Boot updated is crucial for maintaining the integrity and security of Windows PCs.

Jan 15, 2026

The quiet way AI normalizes foreign influence

CyberScoop

The article discusses how AI-generated information is shaping public perception in the U.S., particularly in terms of trusting sources. It points out that while users are becoming accustomed to relying on citations provided by AI, the algorithms do not prioritize credible sources; instead, they favor information that is widely accessible. This can inadvertently normalize foreign influence, as users may not critically assess the origins of the information they receive. The implications are significant, especially as misinformation can spread more easily through AI, potentially impacting public opinion and decision-making processes. The article raises concerns about the need for users to remain vigilant and discerning about the information they consume from AI-generated content.

Jan 15, 2026

PoC exploit for critical FortiSIEM vulnerability released (CVE-2025-64155)

Help Net Security

A serious vulnerability, identified as CVE-2025-64155, has been discovered in Fortinet’s FortiSIEM security platform, allowing unauthenticated remote attackers to execute unauthorized code. This flaw specifically affects the phMonitor service, which is crucial for the operation of FortiSIEM. The release of proof-of-concept (PoC) exploit code has heightened concerns, urging organizations using this software to apply patches immediately. If not addressed, this vulnerability could lead to significant security risks, as attackers could manipulate the system remotely. Organizations should prioritize patching their FortiSIEM deployments to safeguard against potential exploitation.

Jan 15, 2026

From quantum resilience to identity fatigue: Trends shaping print security

SCM feed for Latest

Recent discussions around print security have brought attention to several emerging issues, including AI-driven threats, quantum risks, and identity fatigue. Printers are increasingly seen as vulnerable points in enterprise security systems, primarily because they often lack proper security measures. As organizations adopt more advanced technologies, the potential for quantum computing to break traditional encryption poses a significant risk. Additionally, the concept of identity fatigue—where users become overwhelmed by managing multiple identities and credentials—can lead to negligence in security practices. This situation is concerning for businesses that rely on secure printing solutions, as it could lead to data breaches and unauthorized access.

Jan 15, 2026