frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Analysis of ServiceNow's AI Vulnerability (85% of Fortune 500 Affected)

https://opena2a.org/blogs/servicenow-ai-vulnerability
2•abdelfane•1h ago

Comments

abdelfane•1h ago
Author here. I spent the last week analyzing this vulnerability from a security architecture perspective.

Key insight: This isn't a ServiceNow-specific problem. It's an industry-wide pattern of grafting AI agents onto legacy auth systems.

We built an open-source platform (AIM) that implements the prevention strategies outlined in the article. Happy to answer questions about AI agent security or the analysis.

GitHub: github.com/opena2a-org/agent-identity-management

chrisjj•1h ago
Nice article.

But the "AI" angle is incidental, surely. The provider simply added an unsecured API, period.

abdelfane•1h ago
You're right that at the technical level, it's an unsecured API. But I'd argue the AI context matters for two reasons:

  1. The capability itself: The "create data anywhere" permission wasn't a legacy API—it was added specifically to enable AI agent functionality (Now Assist). Traditional chatbots had scoped, rules-based actions. The shift to agentic AI introduced capabilities that the auth model wasn't designed to govern.

  2. The pattern: This is going to happen repeatedly. Companies are bolting AI agents onto legacy systems without rethinking authorization. ServiceNow is just the first high-profile example. The same pattern exists in Copilot plugins, Claude Desktop MCP servers, LangChain deployments—anywhere AI agents get grafted onto existing infrastructure.
You could call it "an unsecured API" and be technically correct. But the reason it was unsecured is that AI agents break the assumptions traditional IAM was built on: human decision-making, predictable workflows, fixed permissions.

The fix isn't just "secure your APIs" (though yes, do that). It's recognizing that autonomous agents need different authorization primitives than human-operated systems.

FluConf: An online event for Covid-cautious appreciators of FOSS

https://fluconf.online/
1•edward•42s ago•0 comments

The Illiquidity of Water Markets

https://www.restud.com/the-illiquidity-of-water-markets/
1•sebg•1m ago•0 comments

Falcon-H1-Tiny: A series of small, yet powerful language models

https://huggingface.co/spaces/tiiuae/tiny-h1-blogpost
1•ToJans•1m ago•0 comments

When AI writes almost all code, what happens to software engineering?

https://newsletter.pragmaticengineer.com/p/when-ai-writes-almost-all-code-what
1•gmays•2m ago•0 comments

Renfrew Christie has died, sabotaged South Africa's nuclear program

https://www.nytimes.com/2026/01/14/world/africa/renfrew-christie-dead.html
1•NaOH•4m ago•1 comments

You're Getting 'Screen Time' Wrong

https://www.theatlantic.com/technology/2025/10/screen-time-television-internet/684659/
1•Anon84•4m ago•2 comments

Headless blog using SleekCMS, NextJS and Vercel

https://sleekcms-nextjs-blog-1.vercel.app/
1•yusufnb•7m ago•0 comments

Wrist Photoplethysmography Pulse Waves: Morphology and Physiological Influences

https://www.mdpi.com/2673-4591/118/1/83
1•PaulHoule•8m ago•0 comments

Reddit Stock Down 8% After Digg Open Beta Launch

https://finance.yahoo.com/quote/RDDT/
1•madihaa•9m ago•0 comments

L Ellison Renames Yacht After Critics Point Out It Spells "I'm a N*Zi" Backwards

https://calfkicker.com/larry-ellison-quietly-renames-yacht-after-critics-point-out-it-spells-im-a...
2•ndsipa_pomu•9m ago•1 comments

Scientists develop smart transparent woods that block UV and save energy

https://www.thebrighterside.news/post/scientists-develop-smart-transparent-woods-that-block-uv-an...
1•westurner•10m ago•0 comments

Manic Technology

https://www.robinsloan.com/lab/manic-technology/
1•speckx•10m ago•0 comments

Show HN: Not a marketer? Let experts promote your startup FAST

https://sharemrr.com/
1•AzizBelAbed•10m ago•0 comments

The Downside to Using AI for All Those Boring Tasks at Work

https://www.wsj.com/lifestyle/careers/the-downside-to-using-ai-for-all-those-boring-tasks-at-work...
1•gmays•12m ago•1 comments

FDA paves way for more consumer wearables to hit the market

https://www.fiercehealthcare.com/digital-health/fda-paves-way-more-consumer-wearables-hit-market
1•brandonb•12m ago•0 comments

Oracle Trying to Lure Workers to Nashville for New 'Global' HQ

https://www.bloomberg.com/news/articles/2026-01-15/oracle-nashville-hq-trying-to-recruit-cloud-wo...
1•petethomas•12m ago•0 comments

Briar keeps Iran connected via Bluetooth and Wi-Fi when the internet goes dark

https://briarproject.org/manual/fa/
2•us321•13m ago•0 comments

"Hello, Computer." Vocal computing seems primed to take off, for real this time

https://spyglass.org/vocal-computing-ai/
1•ChrisArchitect•14m ago•0 comments

Astrophotography visibility plotting and planning tool

https://airmass.org/
1•NKosmatos•18m ago•0 comments

A.I. Is Keeping Aging Coal Plants Online

https://e360.yale.edu/digest/ai-coal-nuclear
1•speckx•19m ago•0 comments

Shipping a Universe: A Post-Mortem

https://medium.com/@boris.churzin/shipping-a-universe-a-post-mortem-1b75b55b205b
1•devenvdev•19m ago•1 comments

I Did a Daring Fireball Ad

https://www.finalist.works/i-did-a-daring-fireball-ad/
2•slaven•23m ago•0 comments

Show HN: Superfocus – Pomodoro timer built for students

https://www.superfocus.live/
1•Jcjimenez•23m ago•1 comments

Show HN: Stdskill – The skill for wicked coding agents

https://github.com/ZeroAurora/stdskill
1•ZeroAurora•23m ago•0 comments

Health NZ confirms another major tech outage

https://www.rnz.co.nz/news/national/584179/health-nz-confirms-another-major-tech-outage
3•billybuckwheat•23m ago•0 comments

Gail.com

https://gail.com/
2•RyanShook•24m ago•0 comments

Lexica: A word-of-the-day SMS service

https://lexica.io
1•sestarkman•25m ago•0 comments

OpenAI invests $250m in Sam Altman's brain computer interface startup Merge Labs

https://techcrunch.com/2026/01/15/openai-invests-in-sam-altmans-brain-computer-interface-startup-...
2•tobarpal•25m ago•0 comments

Digg launches its new Reddit rival to the public

https://techcrunch.com/2026/01/14/digg-launches-its-new-reddit-rival-to-the-public/
3•madihaa•26m ago•1 comments

Visualize OpenUSD in Rerun

https://github.com/art-e-fact/usd-rerun-logger
1•Tycho87•26m ago•0 comments