ServiceNow discloses security incident exposing customer data
… The security update released on Friday was allegedly used to set requires authentication to true . Numerous admins shared indicators of compromise, including API requests from the IP address ' 51.159.98.241 ,' advising other administrators to review logs for requests to the vulnerable endpoint. …