ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts
Prompt injection attacks can be carried out by malicious actors by taking advantage of default configurations in ServiceNow's Now Assist generative artificial intelligence (AI) platform and using its agentic capabilities.
AppOmni claims that the second-order prompt injection uses Now Assist's agent-to-agent discovery to carry out illegal actions, allowing attackers to alter records, escalate privileges, and copy and exfiltrate confidential company data.
According to Aaron Costello, chief of SaaS Security Research at AppOmni, "this discovery is concerning because it's expected behavior as defined by certain default configuration options, not a bug in the AI."
A innocent request might subtly develop into an attack when agents are able to find and recruit one another, giving crimina...

