ServiceNow Discloses Security Incident — Attackers Exploited Unauthenticated API Endpoint to Query Customer Instance Data
ServiceNow has quietly warned customers that attackers exploited an unauthenticated API endpoint to query data from customer instances. A June 5 update locked the endpoint to authenticated users only. Admins point to /api/now/related_list_edit set to requires_authentication=false.