BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ServiceNow Now Assist AI Vulnerable to Prompt Injection Attacks

ServiceNow's Now Assist AI Platform Vulnerable to Second-Order Prompt Injection Attacks Through Default Agent Discovery Features

  • Default configurations in ServiceNow‘s Now Assist AI platform enable second-order prompt injection attacks.
  • Attackers can exploit agent-to-agent communication to access and modify sensitive data without detection.
  • The issue arises from enabled agent discovery and collaboration features, which are set on by default.
  • Mitigations include supervised execution modes, disabling autonomous overrides, and monitoring agent behavior.

ServiceNow‘s Now Assist generative AI platform is vulnerable to sophisticated prompt injection attacks due to its default settings, allowing malicious actors to exploit its agentic features. Disclosed in November 2025, this security risk arises from the platform’s agent-to-agent discovery capability, enabling unauthorized data access and actions.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to AppOmni, the second-order prompt injection attack leverages Now Assist’s facility for autonomous agents to identify and collaborate with each other. These agents, designed to automate tasks such as help-desk functions, can be manipulated to execute commands including copying sensitive corporate data, altering records, and elevating privileges.

“This discovery is alarming because it isn’t a bug in the AI; it’s expected behavior as defined by certain default configuration options,” stated Aaron Costello, chief of SaaS Security Research at AppOmni. “When agents can discover and recruit each other, a harmless request can quietly turn into an attack, with criminals stealing sensitive data or gaining more access to internal company systems. These settings are easy to overlook.”

The vulnerability stems from three main default configurations: the underlying large language models (LLMs) such as Azure OpenAI LLM and Now LLM support agent discovery; Now Assist agents are grouped into the same team by default, enabling cross-invocation; and agents are published as discoverable automatically. These settings facilitate behind-the-scenes cross-agent communication that attackers can exploit.

In this scenario, a benign agent processing prompts embedded in accessible content may recruit a more capable agent to perform unauthorized tasks. This occurs even if conventional prompt injection protections are in place. Crucially, Now Assist agents operate with the privileges of the user who initiates them, not the malicious actor who inserts harmful prompts.

- Advertisement -

Following responsible disclosure, ServiceNow confirmed the behavior is intended and has updated its documentation for clarity. To reduce risks, organizations should configure supervised execution modes for privileged agents, disable the autonomous override option (“sn_aia.enable_usecase_tool_execution_mode_override”), segment agent roles by team, and actively monitor AI agent activities for suspicious patterns.

“If organizations using Now Assist’s AI agents aren’t closely examining their configurations, they’re likely already at risk,” Costello warned.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin, S&P 500 Correlation Warns of 50% Drop

Bitcoin gave back most of its geopolitical gains this week, moving back toward $68,700...

Hormuz Blockade Sends US Diesel Past $5, Threatens Economy

The US national average price for diesel fuel has surpassed $5 per gallon, a...

‘Hawk Tuah Girl’ Says 2024 Memecoin Implosion “Traumatized” Her

Social media influencer Hailey Welch, known as the "Hawk Tuah girl," says she was...

Nevada judge blocks Kalshi prediction market

A Nevada judge has issued a 14-day temporary restraining order against the prediction market...

CFTC Details Crypto Collateral Rules in Pilot Program

The CFTC has issued new guidance for a pilot program allowing the use of...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading