How can hackers most effectively target and breach ServiceNow's software? The answer often involves customers and service providers that misconfigure the popular IT service management (ITSM) software.Indeed, 70 percent of ServiceNow customer instances suffer from Access Control List (ACL) misconfigurations, according to targeted testing from AppOmni. Those misconfigurations, in turn, can allow probing eyes to potentially fetch Personal Identifiable Information (PII) from ServiceNow instances, the research found.The misconfigurations are especially risky for midmarket MSPs -- many of which now offer co-managed ServiceNow capabilities to their end-customers. Also, some MSSPs increasingly integrate their security software with ServiceNow dashboards to automate incident response. In theory, ServiceNow misconfigurations between shared ITSM systems could trigger supply chain software attacks that spread upstream or downstream between MSPs/MSSPs and end-customers.Proper ServiceNow ACL Configuration Settings: ServiceNow has been quick to address the AppOmni report. MSSPs and MSPs seeking guidance should check out the software company's ServiceNow Shared Security Model and Access Control Information.