BodySnatcher: How a Single Email Address Could Hijack an Enterprise AI Agent
A critical vulnerability in ServiceNow's Virtual Agent API (CVE-2025-12420) allowed attackers to impersonate any user — bypassing MFA and SSO — and execute privileged AI agent workflows. Here's what happened and what it means for agentic AI security.