Now Assist Secrets Revealed: What ServiceNow Partners Don't Want You to Know
I have witnessed firsthand the transformative power of ServiceNow's Now Assist platform, and I've also seen the hidden vulnerabilities that can turn your AI investment into a security nightmare. After working with dozens of enterprises implementing Now Assist across ITSM, ITOM, and HRSD modules, I can tell you there are critical truths about this platform that many ServiceNow partners won't discuss during the sales cycle.
Let me guide you through the essential insights that will protect your organization and maximize your Now Assist ROI.
The BodySnatcher Vulnerability: A Wake-Up Call for AI Security
In January 2025, security researchers uncovered BodySnatcher (CVE-2025-12420), a critical vulnerability in Now Assist AI Agents and Virtual Agent API that should make every CIO pause. This flaw allowed unauthenticated attackers to impersonate any user, including administrators, using nothing more than an email address.
The impact? Complete bypass of multi-factor authentication (MFA), single sign-on (SSO), and other security controls your team worked hard to implement.

I've seen organizations invest six figures in ServiceNow consulting services only to discover their Now Assist implementation exposed them to unauthorized access of customer Social Security numbers, healthcare records, and financial data. The vulnerability affected Now Assist versions 5.0.24 through 5.1.17 and Virtual Agent API versions 3.15.1 and 4.0.0–4.0.3.
The root cause? ServiceNow shipped the platform with a hardcoded, platform-wide secret shared across all customer instances. This design choice, made to provide a seamless user experience, created a security gap that attackers could exploit to create backdoor accounts with full administrative privileges.
While ServiceNow has released patches, this incident reveals a fundamental truth: even the most sophisticated AI platforms can harbor architectural vulnerabilities that traditional security assessments miss.
Second-Order Prompt Injection: The Silent Threat
Beyond BodySnatcher, there's another attack vector that keeps me up at night, and it's one that persists even after patching. Second-order prompt injection attacks exploit ServiceNow's default configurations in ways that are difficult to detect and devastatingly effective.
Here's how it works: A low-privileged user embeds malicious instructions in standard data fields, incident descriptions, catalog requests, or HR case notes. When a higher-privileged AI agent later processes these records, it executes the hidden commands, performing unauthorized actions on behalf of the attacker.

Through Now Assist's agent-to-agent discovery feature, a capability that ServiceNow markets as a strength, compromised agents can recruit more powerful agents to execute a cascade of unauthorized actions. This includes:
Accessing restricted records across ITSM, ITOM, and GRC modules
Modifying critical configuration data
Escalating user privileges
Exfiltrating sensitive information
The most alarming aspect? These attacks work even with Now Assist's protection features enabled. The agent-to-agent Scripted REST API directly injects requests into the execution queue, allowing agents to be executed outside expected channels if a user has sufficient permissions.
During a recent ServiceNow implementation for a healthcare client, I discovered that their default team-based grouping unintentionally enabled risky agent collaboration that could have exposed patient data across departmental boundaries. Configuration weaknesses like insecure Large Language Model (LLM) selection and overly permissive agent grouping create attack surfaces that standard penetration testing won't reveal.
Configuration Weaknesses: The Devil in the Default Settings
This brings me to a critical truth about Now Assist: the out-of-box configuration prioritizes user experience over security. While this accelerates adoption, it creates operational risks that demand strategic foresight during implementation.
I've audited dozens of Now Assist deployments, and I consistently find the same configuration gaps:
1. Insufficient Agent Isolation: Default configurations allow AI agents to communicate and collaborate across functional boundaries. While this enables powerful workflows, it also means a compromised agent in your HRSD module could potentially access data in your ITSM or GRC systems.
2. Weak Execution Controls: The platform ships with minimal restrictions on autonomous agent decision-making. Without proper guardrails, agents can override security controls, modify workflows, and execute actions beyond their intended scope.
3. Inadequate Monitoring: ServiceNow's standard monitoring doesn't provide the near real-time visibility needed to detect malicious AI agent behavior. By the time you spot anomalous patterns in weekly reports, significant damage may already be done.

These aren't hypothetical concerns. I've witnessed a manufacturing client discover that their Now Assist agents had been modifying asset records for weeks before their audit controls flagged the anomaly. The operational impact? A complete inventory reconciliation that cost over $200,000 in consultant hours and delayed their ITAM maturity roadmap by six months.
The Licensing Opacity Problem: Hidden Costs of Consumption
Beyond security, there's a financial secret many ServiceNow partners downplay: the lack of transparency in Now Assist's consumption-based licensing model.
Now Assist charges for "assists", units measuring usage of Now Assist skills, beyond a fixed annual allotment. ServiceNow provides only generic information about what constitutes an assist, making it nearly impossible to accurately predict costs during budgeting cycles.
According to ServiceNow's Q2 2025 earnings call, usage of Now Assist grew 9X between January and June 2025. While ServiceNow celebrates this as platform adoption success, for customers it signals potentially explosive consumption-based costs.
I recently worked with a financial services client who projected $150,000 in annual Now Assist costs based on their ServiceNow partner's estimates. Six months into production, they'd already consumed 80% of their assist allotment, putting them on track for $280,000 in actual costs. The difference? Their partner had underestimated assist consumption in high-volume ITSM workflows by nearly 60%.
What This Means for Your Enterprise
If you're planning a Now Assist implementation, or already running the platform, these revelations demand immediate action. The combination of security vulnerabilities, configuration weaknesses, and licensing unpredictability creates risks that extend far beyond IT operations.
For compliance-driven industries (healthcare, financial services, public sector), the BodySnatcher vulnerability and second-order injection attacks represent potential regulatory violations. A data breach stemming from compromised AI agents could trigger HIPAA, PCI-DSS, or GDPR enforcement actions.
For operational efficiency initiatives, configuration weaknesses undermine the very automation benefits you're seeking. When agents execute unauthorized actions or access restricted data, you lose trust in AI-driven workflows and revert to manual processes, negating your ROI.
For budget forecasting, licensing opacity creates financial uncertainty that affects multi-year digital transformation roadmaps. Without accurate consumption models, you can't confidently scale Now Assist across ITOM, HRSD, FSM, or custom applications.
Protecting Your Now Assist Investment: A Strategic Framework
I've developed a comprehensive mitigation framework that addresses these vulnerabilities while maximizing Now Assist value. This guide will walk you through the essential steps:
1. Implement Supervised Execution: Configure Now Assist to require human approval for high-impact agent actions. This reduces autonomous risk while maintaining workflow efficiency for routine tasks.
2. Disable Autonomous Agent Overrides: Prevent AI agents from bypassing security controls or modifying critical configurations without explicit authorization workflows.
3. Isolate Agent Duties: Restructure agent teams to enforce strict separation of duties across modules. Your HRSD agents shouldn't communicate with ITSM agents unless there's a documented business requirement.
4. Enable Near Real-Time Monitoring: Deploy advanced analytics and alerting to detect malicious AI agent behavior within minutes, not days. Monitor for unusual data access patterns, privilege escalation attempts, and cross-module communications.

5. Conduct Regular Agent Audits: Quarterly reviews of agent permissions, execution logs, and inter-agent communications reveal configuration drift and emerging attack patterns.
6. Establish Consumption Baselines: Instrument your Now Assist deployment to track assist consumption by module, workflow, and user segment. Build accurate forecasting models before scaling to production.
7. Partner with ServiceNow Experts: Work with a ServiceNow partner who prioritizes security architecture and transparent licensing analysis, not just rapid deployment.
The SnowGeek Solutions Difference
At SnowGeek Solutions, we've built our reputation on delivering Now Assist implementations that balance innovation with security, automation with control, and ROI with cost predictability. Our ServiceNow consulting services include comprehensive security assessments, configuration hardening, and consumption modeling that protects your enterprise from the vulnerabilities outlined in this analysis.
I've personally guided clients through Now Assist deployments across banking, healthcare, manufacturing, and public sector organizations. Our methodology addresses security from architecture through production, implements agent isolation and supervised execution by default, and provides transparent consumption forecasting so your budgets remain accurate.
The ServiceNow ecosystem is evolving rapidly with each release, from Washington to Xanadu and beyond, but the fundamentals of secure, cost-effective AI implementation remain constant. You need a ServiceNow partner who understands not just the platform's capabilities, but its limitations and risks.
Your Next Steps Toward Secure AI Success
The secrets revealed in this analysis should inform, not intimidate, your Now Assist strategy. With proper architecture, configuration, and ongoing governance, Now Assist delivers unprecedented operational efficiency and user experience improvements.
Don't let hidden vulnerabilities or licensing surprises derail your ServiceNow investment. Visit the SnowGeek Solutions contact page to share your project details and schedule a comprehensive Now Assist security assessment. Our team will evaluate your current configuration, identify vulnerabilities, and develop a customized mitigation roadmap.
Register with SnowGeek Solutions for platform updates and expert insights delivered directly to your inbox. Stay ahead of emerging vulnerabilities, licensing changes, and best practices that protect your enterprise while maximizing Now Assist ROI.
The future of IT service management belongs to organizations that embrace AI innovation with strategic foresight and security discipline. Let's ensure your ServiceNow implementation achieves operational excellence without compromising the security and cost predictability your stakeholders demand.

Comments