Connect with us

CyberSecurity

ServiceNow Vulnerability Exploited in the Wild Just Days After Disclosure

Published

on

ServiceNow CVE-2026-6875 exploitation

Critical Flaw Under Active Attack

A critical vulnerability in the ServiceNow AI platform is being exploited in the wild, just days after a patch was released. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that can allow an unauthenticated attacker to execute arbitrary code under certain conditions.

ServiceNow rolled out a security update on July 14, confirming that hosted instances had been patched. The catch? Self-hosted customers are on their own — they must install the fixes manually.

Disclosure and Immediate Exploitation

On the same day the patch was announced, cybersecurity firm Searchlight Cyber went public with technical details and a proof-of-concept. That transparency had an almost immediate consequence.

By July 18, threat intelligence firm Defused reported seeing real-world exploitation of CVE-2026-6875. Attackers were clearly leveraging the information Searchlight had released. Initially, Defused claimed the exploit reached the same outcome as Searchlight’s PoC but through a slightly different method. On Monday, however, they issued a correction: closer analysis showed the captured payload was actually identical to Searchlight’s own.

Who’s Behind the Attacks?

Defused’s correction raises an uncomfortable question. There are no other public reports of CVE-2026-6875 being exploited. One plausible explanation? The activity could be coming from within the cybersecurity industry itself — researchers scanning for vulnerable systems.

ServiceNow’s official advisory still states there’s no evidence of active exploitation, and it hasn’t been updated to reflect Defused’s findings.

Vendor Response and Patch Guidance

In a statement to SecurityWeek, a ServiceNow spokesperson said: “ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.”

The spokesperson added that the company has “provided updates and patches designed to address this issue” and encouraged both self-hosted and ServiceNow-hosted customers to apply the relevant patches if they haven’t already. They also offered direct assistance for customers struggling with the patch process.

A Pattern of Researcher-Driven Exploitation

This isn’t the first time ServiceNow has seen this dynamic play out. Last month, the company informed customers about an exploited vulnerability — only to later clarify that the exploitation was the work of security researchers, not malicious actors.

True threat actor exploitation of ServiceNow flaws remains rare. The CISA KEV catalog currently lists only two ServiceNow vulnerabilities, both patched back in 2024.

What Should Organizations Do Now?

The window between disclosure and exploitation is shrinking across the industry. For ServiceNow customers, the calculus is straightforward:

  • Self-hosted instances: Apply the patch immediately. There’s no vendor-managed safety net here.
  • Hosted instances: Verify that ServiceNow has applied the update to your environment. Don’t assume — confirm.
  • Monitor logs: Look for unusual activity that could indicate a sandbox escape attempt, especially if your instance hasn’t been patched yet.

The speed of this exploitation cycle is a reminder that public disclosure is a double-edged sword. It empowers defenders, but it also hands attackers a roadmap. For those running self-hosted ServiceNow, the message is clear: patch now, ask questions later. The longer you wait, the more you’re gambling with your environment’s security.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

Pentera Turns AI Security Workflows into Validation Engines — Here’s How

Published

on

AI security workflows

Why AI Security Decisions Need a Reality Check

AI security agents are no longer just chatty assistants. They’re making actual calls — triaging alerts, prioritizing fixes, even suggesting remediation steps. That’s a big leap from the days when automation stopped at log correlation.

But here’s the problem: most of these agents lean on fragmented signals. Scanner output, severity scores, threat intel, config findings, exposure data. Each one tells a piece of the story, and none of them tells the whole story.

Attackers don’t move through an environment one neat step at a time. They chain exploits, pivot laterally, and exploit gaps between tools. If your AI is making decisions based on siloed data, it’s making decisions in the dark.

What Pentera Does Differently

Pentera has built a platform that treats AI security workflows as something to be tested, not just trusted. Instead of letting agents run on assumptions, Pentera continuously validates them against real attack simulations.

The idea is simple: if an AI agent recommends a remediation, you should know whether that recommendation actually holds up under attack. Pentera’s validation engine does exactly that — it runs safe, controlled exploits against your environment to see if the AI’s decisions would survive contact with a real adversary.

From Signal to Proof

Most security tools give you signals. Pentera wants to give you proof. It takes the AI’s output — the priorities, the suggested actions — and stress-tests them. Did the agent miss a critical path? Did it over-prioritize a low-risk issue? The validation engine surfaces those gaps.

This isn’t theoretical. Pentera’s approach mirrors how penetration testers work, but at machine speed and scale. It’s continuous, not a once-a-year exercise.

The Fragmentation Trap in Modern Security Stacks

Let’s be honest: the average enterprise runs dozens of security tools. Each one generates its own alerts, scores, and dashboards. AI agents are supposed to unify this chaos, but they often just aggregate it.

Aggregation isn’t validation. Just because an AI can summarize findings from five tools doesn’t mean its conclusions are correct. In fact, the more data you feed a model, the more confident it can be — and confidence isn’t accuracy.

Pentera’s pitch is that validation closes this loop. You don’t just ask the AI what to do; you test whether doing it actually works.

How Validation Changes the AI Security Game

When you validate AI decisions against simulated attacks, a few things happen:

  • False confidence drops — agents that look good on paper get exposed quickly.
  • Priorities shift — remediation efforts focus on what actually matters, not what’s loudest.
  • Trust grows — security teams are more likely to act on AI recommendations they’ve seen verified.

That last point is huge. The biggest barrier to AI adoption in security isn’t model quality; it’s trust. Teams won’t let an agent touch production if they can’t verify its judgment.

What This Means for Security Teams

For practitioners, the takeaway is straightforward: start treating AI outputs like hypotheses, not facts. Test them. Pentera’s validation engine is one way to do that, but the mindset matters more than any single tool.

Ask yourself: when your AI flags a critical vulnerability, do you know it’s critical? Or just that it has a high CVSS score? Validation gives you the answer.

It’s also worth considering how this fits into broader automation. If you’re building automated security response workflows, validation should be a checkpoint, not an afterthought. The same logic applies to AI-driven threat prioritization — you need to know the logic holds.

Pentera’s bet is that the future of AI security isn’t smarter models alone. It’s models that are held accountable. That’s a bet worth watching.

Continue Reading

CyberSecurity

SilverFox Deploys 3-Driver BYOVD Chain to Hit Japanese Manufacturer with ValleyRAT

Published

on

SilverFox BYOVD attack

SilverFox’s New Tactic: A Three-Driver Assault

The Chinese-speaking cybercrime crew known as SilverFox has shifted gears. Instead of relying on a single vulnerable driver, they’re now chaining three different ones in a bring your own vulnerable driver (BYOVD) attack. The target? A Japanese organization in the industrial manufacturing sector. The goal? Dropping ValleyRAT (also tracked as Winos 4.0) for persistent remote access.

This isn’t just another malware campaign. It’s a deliberate evolution in technique, combining newly observed vulnerable-driver abuse with abuse of legitimate software—a mix that makes detection significantly harder.

How the BYOVD Chain Works

In this campaign, SilverFox leverages a trio of drivers to bypass security controls. Each driver serves a specific purpose: one to disable or tamper with endpoint protection, another to gain kernel-level privileges, and a third to maintain stealth. The chain is designed to work in sequence, with each step paving the way for the next.

  • Driver 1: Disables security software (anti-virus, EDR).
  • Driver 2: Elevates privileges to kernel mode.
  • Driver 3: Provides persistence or hides malicious activity.

Once the drivers do their job, the attackers drop ValleyRAT—a remote access trojan that gives them full control over the infected machine. ValleyRAT isn’t new, but its delivery via a three-driver BYOVD chain is a notable escalation.

Why Target a Japanese Manufacturer?

Industrial manufacturing is a high-value target. These organizations often run legacy systems, have high uptime requirements, and can’t afford downtime for security patches. That makes them attractive to cybercriminals seeking long-term access for data theft, ransomware staging, or industrial espionage.

SilverFox has a history of targeting East Asian entities, but this specific focus on a Japanese manufacturer suggests either a strategic shift or a tailored operation. The use of ValleyRAT—a tool commonly associated with Chinese-speaking threat actors—reinforces the group’s profile.

BYOVD Attacks: A Growing Trend

BYOVD attacks aren’t new, but they’re becoming more common. The technique exploits signed, legitimate drivers that have known vulnerabilities. Attackers load these drivers to perform privileged operations that would otherwise be blocked.

What’s concerning here is the multi-driver approach. Most BYOVD attacks use a single driver. Chaining three suggests a more sophisticated operation, likely with custom tooling or at least careful planning. It also complicates mitigation—blocking one driver isn’t enough if two others can still be abused.

Defending Against Multi-Driver BYOVD

For defenders, the key is layered protection. Relying on a single security control is no longer viable. Here are some practical steps:

  • Maintain an up-to-date blocklist of known vulnerable drivers.
  • Use memory integrity and virtualization-based security (VBS) to prevent driver loading.
  • Monitor for unusual driver load events in your SIEM.
  • Segment networks to limit lateral movement post-compromise.

These measures won’t stop every attack, but they raise the bar significantly.

ValleyRAT: More Than Just a Backdoor

ValleyRAT, also known as Winos 4.0, is a feature-rich trojan. It supports keylogging, screen capture, file exfiltration, and command execution. In this campaign, it’s used for persistent remote access—meaning the attackers can return anytime they want.

The malware is often delivered via phishing emails or exploit kits, but the BYOVD chain here adds a layer of sophistication. It’s a reminder that even known malware can be dangerous when paired with novel delivery mechanisms.

What This Means for Industrial Security Teams

If you’re in manufacturing, this is a wake-up call. The attackers aren’t just targeting IT systems; they’re after operational technology (OT) and intellectual property. A successful breach could mean stolen designs, disrupted production, or worse.

Security teams should review their driver policies, audit existing allowlists, and ensure that endpoint protection is configured to detect anomalous driver behavior. Regular threat hunting for ValleyRAT indicators is also advisable.

For more on related threats, check out our analysis of ValleyRAT malware delivery methods and BYOVD attack mitigation strategies.

Final Thoughts

SilverFox’s three-driver BYOVD chain is a clear signal: cybercriminals are getting more creative with their toolkits. The attack on the Japanese manufacturer shows that no sector is off-limits, and no single defense is sufficient.

Staying ahead requires vigilance, continuous monitoring, and a willingness to adapt. The threat landscape is evolving—are your defenses keeping pace?

Continue Reading

CyberSecurity

Read This Before You Buy That TV Streaming Stick: Inside the H96 Ad Fraud Network

Published

on

TV streaming stick ad fraud

The Cheap TV Stick That’s Actually a Click-Farming Bot

You see them on Amazon for $30 or $40. They promise free movies, live sports, and endless channels — no subscription needed. They’re called H96 streaming sticks, and they look like a bargain. But a new investigation from security firm Bitsight TRACE reveals these devices aren’t just a privacy risk. They’re part of a sophisticated ad fraud network that turns your living room into a cash machine — for someone else.

Researcher Pedro Falé bought an expired domain once used by thousands of H96 boxes for telemetry. What he found inside was a sprawling operation. The devices weren’t just streaming Netflix. They were masquerading as Samsung, Vivo, Huawei, and Xiaomi smartphones, clicking ads on AI-generated websites. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones,’” Falé said. “Something was wildly wrong.”

This is the story of how a cheap TV streaming stick ad fraud network works — and why you should think twice before plugging one in.

How H96 Devices Fake Being Phones

Bitsight TRACE tracked roughly 38,000 H96 boxes worldwide phoning home to that expired domain. Each device reported its hardware specs and a full list of installed apps. But the data showed something odd: every box claimed to be a mobile phone model from a major manufacturer. The same two apps were installed on all of them, both made by a Chinese company called Zhejiang Fengwo IoT Technology Ltd, operating under the Fengwo Group.

Falé dug deeper. He found that Fengwo Group had registered patents matching the apps’ behavior. The apps coordinate a network where H96 devices serve as “captive traffic sources.” They visit websites — also run by Fengwo — that only display ads when the visitor matches a spoofed mobile profile. The boxes click those ads, generating revenue from advertisers who think they’re reaching real people on phones.

The websites themselves are bizarre. Bitsight found machine-generated news articles on finance, health, education, gaming, and food blogs. No human wrote them. AI did. And the sites only show ads to the spoofed devices. To a normal browser, they appear ad-free.

Blockly: The Drag-and-Drop Malware Factory

Fengwo Group’s homepage claims it has created more than 120,000 “AI digital humans” for rent — for companionship, customer service, or creative design. Bitsight’s report suggests this might be a cover story. But the real ingenuity lies in how the fraud is built.

The group uses a Google-built visual programming language called Blockly, originally designed to teach kids to code. Fengwo’s employees drag and drop code blocks in a Blockly editor to define fraud routines. “An operator doesn’t need as much understanding of the underlying technicalities,” Bitsight’s report notes. “Only a small number of highly-skilled developers are needed to build the template execution-unit images.”

When an H96 box is selected for a task, it receives the appropriate Blockly module. That module can silently launch a browser, visit pages, manage tabs, and click ads. The system fuses three vision and reasoning systems into one interface, letting bots identify ads on a page and navigate like a human. It’s ad fraud made easy — no coding skills required.

When Your TV Is On, Your Internet Is for Rent

Bitsight discovered a chilling pattern. When the H96 box detects an HDMI signal — meaning you’re watching something — it switches to residential proxy mode. That means it rents your home’s IP address to strangers: content scrapers, ticket scalpers, even cybercriminals. When the TV is off, the box flips back to ad fraud mode, waiting for its next click job.

Falé believes the device is designed this way because ad fraud tasks are resource-heavy and would interfere with streaming video. So the box only runs fraud when you’re not using it. But the proxy software runs whenever the TV is on. Either way, your network is being used without your knowledge.

These devices are also notoriously insecure. They ship with no authentication, default passwords, and outdated Android builds. In January, the proxy tracking service Synthient documented how botnets enslaved millions of TV boxes by exploiting vulnerabilities in both the proxy software and the hardware itself. Plug one in, and you’re inviting attackers onto your network.

The $50,000-a-Day Business Model

Bitsight estimates the Fengwo Group’s ad fraud network generates close to $50,000 per day — and that’s from just one old domain. The actual revenue, including the residential proxy side, could be much higher. “These estimates are highly conservative,” Falé said.

Despite repeated warnings from the FBI and security firms, major e-commerce platforms like Amazon, Best Buy, and Newegg continue to sell hundreds of models that bundle unofficial Android versions. They’re marketed by influencers as a way to stream premium content for free. But the real cost is your privacy, your network security, and your bandwidth.

Fengwo Group did not respond to requests for comment. Emails to its contact address bounced back with a message that the inbox was full — or “getting too much mail right now.”

How to Protect Yourself

The safest move is simple: stick to name-brand streaming devices from reputable manufacturers. Google provides a way to check if a device is certified for Android TV OS and Play Protect. Synthient also maintains a list of IoT devices known to ship with pre-installed proxy software and malicious apps. That list includes not just streaming sticks but also digital photo frames — another popular category the FBI has flagged.

Even with a trusted device, be careful what apps you install. Many third-party apps bundle residential proxy software. If a deal sounds too good to be true — a $30 stick that unlocks all the world’s TV — it almost certainly is. The real price is your home network, turned into a tool for fraud.

Continue Reading

Trending