ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing

ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing

•

Episode description

ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing

Three critical threats demand immediate attention today. A remote code execution vulnerability in ServiceNow’s AI Platform (CVE-2026-6875) is now actively exploited in the wild, requiring urgent patch verification from direct users and managed service providers alike. Meanwhile, a vishing campaign running since April has been successfully defeating Microsoft 365 passkey enrolment through carefully scripted social engineering, targeting UK SMBs who adopted phishing-resistant MFA but failed to brief staff on the human attack vector. The third story examines FortiBleed, an industrial-scale FortiGate credential harvesting operation exposed when attackers left their staging server accessible, revealing 36 rented GPUs running distributed password cracking as a production workflow. The episode also covers the Cruciferra crypter service, which offers high-quality endpoint evasion as a purchased feature, and the Hugging Face breach involving an autonomous AI agent. Each story includes specific, actionable guidance for UK organisations, with particular emphasis on the ServiceNow vulnerability requiring same-day verification from users and their supply chain.

Chapters

  • Introduction Mauven flags three threats requiring immediate action, particularly a ServiceNow vulnerability that has moved from patch-available to actively exploited. The episode will cover required responses for ServiceNow users, Microsoft 365 passkey vishing, and industrial-scale FortiGate credential harvesting.
  • CVE-2026-6875: ServiceNow AI Platform RCE Under Active Exploitation Critical remote code execution vulnerability in ServiceNow AI Platform confirmed under active exploitation. Direct users must verify patch status immediately. Indirect exposure through managed service providers presents significant risk to UK SMBs. Specific guidance provided on what questions to ask providers and when patch confirmation is required.
  • Call to Action Brief encouragement to follow the show and share with colleagues who need the briefing.
  • O-UNC-066: Vishing Actors Defeating Microsoft 365 Passkey Enrolment Campaign active since April uses phone-based social engineering to register attacker-controlled passkeys to victim Microsoft 365 accounts. Attackers use domains containing ‘passkey’, impersonate Microsoft support, and guide targets through fake enrolment while simultaneously registering their own credentials. Three-part mitigation: restrict enrolment policies in Entra, brief staff on the attack pattern, and focus training on reception and finance staff most likely to receive calls.
  • FortiBleed: Industrial-Scale VPN Credential Harvesting Exposed attacker staging server reveals large-scale FortiGate credential harvesting using 36 rented GPUs for distributed password cracking. Operation uses credential reuse, brute force, and GPU-accelerated hash cracking as an industrial workflow. Likely feeds initial access broker market serving ransomware operators. Guidance provided on verifying patch status, rotating credentials, and reviewing authentication logs.
  • Also on the Radar Two additional items: Cruciferra crypter service offering high-quality endpoint evasion including BYOVD-based EDR tampering as a purchased feature, and Hugging Face breach involving autonomous AI agent access to production infrastructure and credentials. Both items flag direction of travel rather than immediate operational response.
  • Closing Summary Recap of required actions: ServiceNow patch verification today, Microsoft 365 Entra policy review and staff briefing on vishing, FortiGate patch status and credential rotation. Emphasises that attackers operate at industrial scale while effective defences require consistent follow-through on straightforward measures.

Links

No transcript available for this episode.