AI Infrastructure Breach Wave: ServiceNow, Hugging Face, DigiCert, Abbott/EY
Four breaches, four victims, one repeated mechanism: the patch-to-deployment gap and a trusted vendor workflow, not a novel exploit.
Threat Briefing
The exploit code behind CVE-2026-6875 routes through ServiceNow's AI Platform differently than the proof-of-concept Searchlight Cyber published -- so detection tuned to the known PoC traffic is blind to live attacks. That gap between patch, PoC, and in-the-wild exploitation is the throughline across every incident this cycle, not a single novel technique.
Attack Surface Analysis
Four incidents, one mechanism: the compromise ran through infrastructure or a workflow the victim didn't fully own or monitor.
| Incident | Vector | Confirmed Impact |
|---|---|---|
| ServiceNow AI Platform | Unauthenticated RCE via undocumented code path | Active exploitation confirmed days post-patch |
| Hugging Face | Poisoned dataset → autonomous agent execution | Cloud/cluster credential theft, lateral movement across sandboxes |
| DigiCert (GoldenEyeDog) | Support-workflow compromise → forged code-signing certs | SmartScreen bypass, Golden Gh0st RAT delivery since April 2026 |
| Abbott/Exact Sciences (ShinyHunters) | Vishing → Entra SSO takeover | Pivot into ServiceNow, SharePoint, Databricks, Coupa |
The Hugging Face chain deserves the closest read: a malicious dataset abused code-execution paths in data processing, escalated to node-level access, and moved autonomously across thousands of short-lived sandboxes -- no human operator pivoting by hand. EY's third-party ITSM breach sat undetected roughly four weeks. None needed a novel exploit; all needed only the gap between disclosure and full remediation, or between a trusted vendor workflow and its actual security posture.
Your Defense Playbook
- Confirm every self-hosted ServiceNow AI Platform instance is on the July 13, 2026 release; verify hosted instances got the vendor-side patch.
- Rotate all Hugging Face tokens and pull API logs for anomalous activity in the breach window.
- Hunt for Golden Gh0st RAT indicators and flag Authenticode-signed binaries tracing to DigiCert certificate serials.
Four breaches, zero zero-days: the exposure was the patch-to-deployment gap and the phone call that convinced a helpdesk to reset a password.
What to do
Patch or confirm vendor-side patching of all ServiceNow AI Platform instances to the July 13, 2026 release -- active exploitation via a second code path is confirmed.
Rotate all Hugging Face access tokens and audit API logs for anomalous activity in the breach window.
Enforce phishing-resistant MFA on all Entra ID/SSO accounts and brief helpdesk staff on vishing this quarter using the Abbott pivot as the training scenario.