<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ServiceNow Security Lab</title>
    <description>Keeping your workflows secure.</description>
    <link>https://securitylab.servicenow.com/</link>
    <atom:link href="https://securitylab.servicenow.com/feed.xml" rel="self" type="application/rss+xml"/>
    <pubDate>Thu, 04 Dec 2025 07:09:20 -0800</pubDate>
    <lastBuildDate>Thu, 04 Dec 2025 07:09:20 -0800</lastBuildDate>
    <generator>Jekyll v3.10.0</generator>
    
      <item>
        <title>DEFCON31 - ELF 64-bit Stack-Based Buffer Overflow</title>
        <description>Recently had the pleasure of attending DEFCON31 at Caesars Forum in Las Vegas. A few of us on the Red Team decided to...</description>
        <pubDate>Tue, 05 Sep 2023 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2023-09-05-defcon31-hackthebox-ctf/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2023-09-05-defcon31-hackthebox-ctf/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>Defeating MFA Number Challenges through Phishing</title>
        <description>Push verifications with an extra number challenge step have become a popular multi-factor authentication strategy. But does this extra step actually offer any added protection against hackers?</description>
        <pubDate>Wed, 06 Sep 2023 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2023-09-06-defeating-mfa-number-challenges/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2023-09-06-defeating-mfa-number-challenges/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>Thinking About CVE-2023-21967, an OpenJDK Vulnerability</title>
        <description>We will analyze and build a POC for CVE-2023-21967, a vulnerability in OpenJDK.</description>
        <pubDate>Fri, 06 Oct 2023 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2023-10-06-openjdk-vuln-reproduction-CVE-2023-21967/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2023-10-06-openjdk-vuln-reproduction-CVE-2023-21967/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>Practical Jazzer for the Snazzy Fuzzer</title>
        <description>We will review some lessons learned and tips for effectively fuzzing your applications with Jazzer.</description>
        <pubDate>Mon, 28 Oct 2024 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2024-10-28-jazzer-practical-tips/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2024-10-28-jazzer-practical-tips/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>A Rhino of a Problem - Assembling Call Stacks for Rhino Polyglot Code</title>
        <description>This blog post demonstrates Rhino Tracker, a solution for analyzing Rhino polyglot code.</description>
        <pubDate>Mon, 04 Nov 2024 00:00:00 -0800</pubDate>
        <link>https://securitylab.servicenow.com/research/2024-11-04-a-rhino-of-a-problem/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2024-11-04-a-rhino-of-a-problem/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>SootUp vs. Soot - Is The New Static Analysis Library Ready For Use?</title>
        <description>This blog post compares the static analysis library SootUp to its predecessor Soot to determine areas of improvement, areas that still need work, and how fit SootUp is to be used in actual tool development.</description>
        <pubDate>Tue, 12 Nov 2024 00:00:00 -0800</pubDate>
        <link>https://securitylab.servicenow.com/research/2024-11-12-sootup-vs-soot/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2024-11-12-sootup-vs-soot/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>SNulk - ServiceNow Bulk Submit Tool for Table Records</title>
        <description>This post introduces SNulk, a solution that allows users to effortlessly submit large numbers of templated records to a table on a ServiceNow instance.</description>
        <pubDate>Tue, 14 Jan 2025 00:00:00 -0800</pubDate>
        <link>https://securitylab.servicenow.com/research/2025-01-14-snulk/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2025-01-14-snulk/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>Binary Data Analysis: The Role of Entropy</title>
        <description>This is the first article in a series for binary data analysis. It is an introduction to entropy.</description>
        <pubDate>Mon, 07 Apr 2025 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2025-04-07-Binary-Data-Analysis-The-Role-of-Entropy/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2025-04-07-Binary-Data-Analysis-The-Role-of-Entropy/</guid>
        
        
        <category>research</category>
        
      </item>
    
      <item>
        <title>Binary Segmentation: Entropy as a Cost Function</title>
        <description>This is the first article in a series for binary data analysis. It provides an approach to using entropy as a cost function for binary segmentation.</description>
        <pubDate>Wed, 04 Jun 2025 00:00:00 -0700</pubDate>
        <link>https://securitylab.servicenow.com/research/2025-06-04-Binary-Segmentation-Entropy-As-A-Cost-Function/</link>
        <guid isPermaLink="true">https://securitylab.servicenow.com/research/2025-06-04-Binary-Segmentation-Entropy-As-A-Cost-Function/</guid>
        
        
        <category>research</category>
        
      </item>
    
  </channel>
</rss>
