BodySnatcher: Virtual Agent Impersonation (CVE-2025-12420)
Is my instance vulnerable to BodySnatcher?
Written from the attacker's side and verified against a live ServiceNow instance rather than generated from training data. Each article carries the read-only detection script that produced the finding, the remediation, and the regulatory citation an auditor will ask for.
Is my instance vulnerable to BodySnatcher?
Are my ACLs on hr_case secure?
GlideRecord vs GlideRecordSecure in widgets
How does instance cloning expose production data in sub-production?
How do I secure MID Servers in ServiceNow?
NIS2 incident reporting ServiceNow
How can Now Assist be exploited via prompt injection?
CVE-2026-0542 ServiceNow
Is my ServiceNow SAML SSO configuration secure?
Is my instance vulnerable to CVE-2026-6875?
Are there passwords stored in ServiceNow records?
How to audit service accounts in ServiceNow
Is my ServiceNow portal exposed to the internet?
What domain separation cannot protect against
How does OWASP Agentic AI Top 10 apply to ServiceNow?
How to collect forensic evidence from ServiceNow?
What certifications does ServiceNow hold?