← Back to feed
TechJun 1086% confidenceConfidence 86% — the share of independent, credible sources corroborating the core facts.

ServiceNow Patches API Vulnerability That Exposed Customer Data to Unauthenticated Access

Center 100%
3 sources

ServiceNow applied a security fix on June 5, 2026, after a bug in an API endpoint allowed unauthenticated users to query customer instance tables containing sensitive enterprise data. The issue primarily affected customers running the Australia platform release or older versions with certain configuration changes. The incident highlights the risk posed by cloud platforms that aggregate large volumes of sensitive corporate data, though ServiceNow says the access came from security researchers rather than malicious actors.

ServiceNow notified affected enterprise customers that a software bug had allowed unauthenticated users to gain unintended access to data stored in customer instances, including potentially sensitive information such as IT support tickets, employee records, and credentials. A patch was applied on June 5, 2026, restricting the affected API endpoint to authenticated users only. ServiceNow told TechCrunch the activity was not a hack but was carried out by security researchers participating in a bug bounty program, who confirmed no data was retained or misused. The issue primarily affected customers on the Australia platform release, though Reddit users reported evidence of access on other versions as well. Customers who received a support case from ServiceNow were directly notified; those without an open case were told no anomalous activity was observed on their instances. Network defenders identified IP address 51.159.98.241 as an indicator of compromise, and administrators are advised to review logs for requests to the /api/now/related_list_edit endpoint, rotate exposed credentials, and ensure API logging is enabled. ServiceNow said it is evaluating whether to publish a CVE.

What's missing

It remains unclear how many customer instances were actually accessed, and whether ServiceNow's characterization of the activity as solely bug bounty research has been independently verified. The identity of the security researchers has not been disclosed.

How coverage differed

TechRadar framed the incident with more uncertainty, describing the actors as 'cybercriminals' and emphasizing what ServiceNow would not disclose, while TechCrunch obtained a direct statement from ServiceNow attributing the activity to security researchers conducting bug bounty work, presenting a notably less alarming picture of the incident.

What different sources said

  • ServiceNow to customers: A bug may have exposed your data on the internet

  • ServiceNow tells customers a bug left some of their data exposed to the internet

  • TechRadarCenter

    ServiceNow reveals security issue affecting customer data, but won't reveal much on what actually happened

Related

TechConfidence 69% — the share of independent, credible sources corroborating the core facts.

Samsung Galaxy S25 and S25 FE See Significant Price Cuts

Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

2 sourcesJun 16
TechConfidence 100% — the share of independent, credible sources corroborating the core facts.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order

Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

4 sourcesJun 16
TechConfidence 89% — the share of independent, credible sources corroborating the core facts.

Xbox Free Play Days Offers Three Games Free to Play June 11–14

Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.

2 sourcesJun 13