Swissky[verified]@pentest_swisskyDisclosure
The post announces a new ServiceNow vulnerability (CVE-2025-12420) involving broken authentication and agentic hijacking, but provides no evidence of exploitation, PoC, or patch status.
Blue Team News[verified]@blueteamsec1Disclosure
The post announces a broken authentication and agentic hijacking vulnerability (CVE-2025-12420) in ServiceNow, but offers no proof of concept, exploit code, or patch information.
VulnTracker[verified]@vuln_trackerGeneral
The post references CVE‑2025‑12420 via a dashboard link and notes a new "Agentic hijacking" attack class, but offers no proof‑of‑concept, exploit code, or mitigation details.
Rav[verified]@_MrDecentralizeActive Exploitation
ServiceNow CVE‑2025‑12420 enabled unauthenticated admin impersonation via a hardcoded secret in the Virtual Agent API; evidence suggests this flaw has been exploited at Fortune 100 scale, bypassing MFA, SSO, and other controls. No patches or PoC details are provided.
Rav[verified]@_MrDecentralizeDisclosure
The post explains CVE‑2025‑12420 as a flaw where authentication is performed but no per‑action authorization checks exist, enabling impersonation and privilege escalation in multi‑agent workflows, but it does not mention any PoC, exploit, patch, or active exploitation.
Komodo Cyber Security[verified]@KomodosecGeneral
The tweet highlights a ServiceNow flaw (CVE‑2025‑12420) that permits unauthenticated impersonation, but offers no further technical or mitigation details.
StratoKey@StratoKeyDisclosure
An article announces ServiceNow CVE‑2025‑12420, highlighting weak API authentication and identity linking vulnerabilities that can be exploited through agentic AI workflows; no PoC, exploit, or patch details are provided.
The Agent Economist@The_Agent_EconPatch
The tweet warns of critical zero‑click vulnerabilities affecting Microsoft Copilot, ServiceNow, and Langflow, urging immediate auditing and patching.