

Aaron Costello
308 posts

@ConspiracyProof
🇮🇪 ✝️ Chief of SaaS Security Research @ AppOmni Opinions may be that of James Joyce or Samuel Beckett who occasionally channel their spirits through me.






‼️ New Research Drop ‼️ I’m excited to share my latest @AppOmniSecurity Labs research: a CVSS 9.3 critical vulnerability in #ServiceNow’s AI platform. It's dubbed "BodySnatcher" (CVE-2025-12420) because of its novel exploit path: it allowed an unauthenticated attacker to impersonate any user on the platform and execute powerful out-of-the-box (OOB) AI agents with the victim's permissions. The result? Complete platform takeover. Read my write-up here for the juicy technical details: appomni.com/ao-labs/bodysn… #cybersecurity #ai #saas #vulnerability







A Dublin cybersecurity researcher, Aaron Costello, has found that 1.1 million NHS employee records were leaked online because of improper configuration settings in Microsoft Power Pages breakingnews.ie/ireland/irish-…

Want to know how you can hack Microsoft Power Page websites? How I was able to access (and later secure) PII of 1.1 MILLION #NHS employees? With my latest blog post, you can learn how to pentest a Power Page site for data leaks in as little as 2 minutes. Check it out below: appomni.com/ao-labs/micros… #bugbounty



Want to know how I could've hacked thousands of Oracle NetSuite sites in order to extract sensitive information? It was so severe that within days, Oracle rolled out multiple hardening measures to reduce the risk of it happening again. If you're a pentester, security engineer, NetSuite admin or a bug bounty hunter, this is a must read as I can guarantee that these issues will rear their again head in the future!



A prevention guide for the HSE data leak that left the vaccination information of one million people available was published one year before the incident, according to the security researcher who brought it to light. breakingnews.ie/ireland/preven…


