Quick Summary
The Securityish Brief
The recently identified vulnerability CVE-2025-12420, dubbed ‘BodySnatcher,’ poses a severe threat to organizations using ServiceNow’s Now Assist AI platform. This platform is utilized by almost half of Fortune 100 companies, making the implications of this flaw particularly concerning. The vulnerability allows unauthenticated attackers to impersonate administrators using only an email address, bypassing multi-factor authentication and single sign-on protections. With a CVSS score of 9.3 out of 10, the risk is substantial.
The attack exploits a hardcoded secret within the platform and relies on flawed account-linking logic that trusts email addresses without further verification. This design flaw enables attackers to create backdoor accounts with full privileges, effectively turning enterprise AI agents into tools for malicious activities.
Organizations rushing to deploy AI features often overlook essential security measures, leading to vulnerabilities like BodySnatcher. The pressure to integrate AI capabilities can result in hasty implementations where security becomes an afterthought. Default configurations in AI platforms frequently allow for second-order prompt injection attacks, where malicious instructions can be embedded in data fields.
Agentic AI systems, which operate autonomously and make decisions, significantly expand the attack surface compared to traditional APIs. When AI agents are granted the ability to manage user accounts, they become potential targets for exploitation through various attack vectors, including broken authentication and prompt injection.
The Model Context Protocol (MCP) further complicates security by allowing AI systems to connect to various data sources without adequate authentication. This can expose critical internal tools and databases to attackers who can hijack AI agents’ identities, gaining access to sensitive information without direct authentication.
To mitigate these risks, organizations must prioritize security in their AI initiatives. Implementing zero-trust architectures, eliminating dangerous default configurations, and establishing lifecycle management for AI agents are crucial steps to prevent exploitation.
Why This Matters for Your Security
The BodySnatcher vulnerability underscores the urgent need for organizations to reassess their AI deployment strategies. As AI technologies evolve, so do the associated risks. Companies must ensure that security is not an afterthought but a foundational aspect of their AI systems. The choice between rapid deployment and robust security is clear; prioritizing security can prevent severe vulnerabilities that could compromise entire enterprises.
Key Takeaways
- Conduct a security review for all AI initiatives before deployment to identify potential vulnerabilities.
- Implement zero-trust architecture for AI agents to ensure explicit authentication and authorization for every operation.
- Disable dangerous default configurations in AI platforms to prevent unauthorized access.
- Establish monitoring and anomaly detection for AI agent behavior to quickly identify potential exploitation.
- Regularly audit AI agents to ensure they are necessary and have appropriate privileges.
Key Terms & Concepts
- CVE-2025-12420: In this article, CVE-2025-12420 refers to a critical vulnerability in ServiceNow’s Now Assist AI platform that allows unauthorized access.
- BodySnatcher: BodySnatcher is the name given to the CVE-2025-12420 vulnerability, highlighting its ability to enable impersonation of administrators.
- Model Context Protocol (MCP): MCP is a protocol that allows AI systems to connect to various data sources, often without requiring adequate authentication.
- zero-trust architecture: Zero-trust architecture is a security model that requires strict verification for every user and device trying to access resources.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.