Cybersecurity Brief

Exploited ServiceNow flaw and stealthy Microsoft 365 C2 rise

Today’s reporting highlights two converging operational risks: critical enterprise platform exploitation and increasing stealth in command-and-control. Attackers are already leveraging a critical ServiceNow code execution vulnerability, indicating rapid weaponization and fast-moving defensive urgency for ServiceNow environments. In parallel, new malware uses Microsoft Graph via compromised Microsoft 365 mailboxes as a covert C2 pathway, which increases the likelihood that traditional network detections may underperform.

A third, more forward-looking risk signal is the expansion of ransomware/agentic attack focus toward AI model and dataset assets. JadePuffer’s updated “agentic” behavior reportedly targets AI training data and model checkpoints for encryption, suggesting threat actors are adapting to protect not only user data but also the organizations’ ability to train, fine-tune, and operate AI systems. Finally, a separate incident in Romania demonstrates how cyber disruption can directly impact national economic/operational continuity (land registry), reinforcing the need for resilient incident response and prioritized recovery planning.

Top Signals

1. Critical ServiceNow code execution flaw is actively exploited

Signal strength: Early

Active exploitation of a critical ServiceNow code execution vulnerability raises the likelihood of near-term compromise at scale through widely deployed enterprise workflows. Executives should treat ServiceNow hardening and patch verification as an immediate priority to reduce ransomware, data theft, and lateral movement risk.

Supporting evidence

2. Microsoft 365 Graph used for stealthy C2 and exfiltration

Signal strength: Early

Malware that leverages Microsoft Graph and mailbox features for C2 can blend into normal cloud traffic patterns and reduce visibility for perimeter-based controls. Security leaders should reassess detections around Microsoft 365/Graph usage, mailbox-triggered behaviors, and anomalous exfiltration paths.

Supporting evidence

3. Agentic ransomware targets AI training data and checkpoints

Signal strength: Early

Targeting AI model data (training datasets, vector databases, model checkpoints) expands ransomware impact from confidentiality to availability and operational capability. This creates a business continuity and recovery challenge for organizations using AI for core functions, requiring AI asset inventorying and restore strategies.

Supporting evidence

4. Cyberattacks increasingly disrupt critical national services

Signal strength: Early

A disrupted land registry can directly affect property transactions and economic operations, demonstrating the real-world consequences of cyber incidents beyond data breaches. Executives should ensure recovery plans include service-specific continuity, priority data restoration, and operational coordination across stakeholders.

Supporting evidence

5. Abuse of legitimate networking update paths for targeting

Signal strength: Early

Using the update mechanism of private networking software to deliver malicious activity suggests attackers are targeting trust boundaries in software supply/update channels. This increases the need for rigorous vendor/update verification, integrity controls, and monitoring for tampered update behavior—especially in government-facing environments.

Supporting evidence

Sources