Vendor
Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform
3 TTPsServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.
City Forum Campaign Scraping Salesforce and ServiceNow Portals
1 rule 1 TTP 1 IOCA persistent threat actor is utilizing a single VPS infrastructure to perform unauthorized data scraping from Salesforce and ServiceNow guest portals by exploiting over-privileged guest account permissions.
City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access
2 TTPs 2 IOCsAn unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)
3 CVEsServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.
Remote Code Execution Vulnerability in ServiceNow AI Platform
2 TTPsA remote, anonymous attacker can exploit a vulnerability in ServiceNow AI Platform to execute arbitrary program code, leading to unauthorized control over the platform's underlying systems.