
MitigatedServiceNow hosted customer instances (API endpoint)
ServiceNow Patches Unauthenticated API Endpoint After Data-Exposure Incident
ServiceNow patched a misconfigured API endpoint that allowed unauthenticated queries of customer instance data, and observed successful table queries for a subset of customers - but says the activity appears attributable to security researchers, with no evidence data was retained or misused.
