Topic: saas security

  • SaaS Security: A New Framework for Essential Controls

    SaaS Security: A New Framework for Essential Controls

    Modern enterprises face significant challenges securing their diverse SaaS portfolios due to fragmented security settings and inadequate traditional vendor assessments. The Cloud Security Alliance introduced the SaaS Security Capability Framework (SSCF) to standardize security controls, enabling ...

    Read More »
  • The Hidden Cost of a Security Breach

    The Hidden Cost of a Security Breach

    Companies are shifting security budgets reactively after breaches, but this emergency spending is far more costly than proactive investment, often exceeding it by a factor of nine. The rise of new attack vectors, especially targeting SaaS data, increases breach likelihood and financial damage, ye...

    Read More »
  • Boost SaaS Security with NIST CSF & Agentic AI

    Boost SaaS Security with NIST CSF & Agentic AI

    The rapid adoption of SaaS and AI often outpaces security, creating risks; the NIST Cybersecurity Framework provides a structured blueprint to balance innovation with robust protection. Effective security requires strong governance and collaboration between InfoSec and SaaS teams, alongside criti...

    Read More »
  • Mitiga launches Agentic Runtime Security for cloud, SaaS, AI

    Mitiga launches Agentic Runtime Security for cloud, SaaS, AI

    Mitiga's Agentic Runtime Security redefines runtime detection and response for modern infrastructure (cloud, SaaS, identity, AI) by using log-based defense instead of endpoint agents, enabling real-time behavioral detection and containment where traditional EDR cannot reach. The approach addresse...

    Read More »
  • AppOmni’s Marlin AI automates SaaS threat response at scale

    AppOmni’s Marlin AI automates SaaS threat response at scale

    AppOmni launched Marlin AI, an autonomous AI solution that defends complex SaaS environments by correlating security indicators, conducting investigations, and delivering actionable guidance, eliminating manual threat analysis. Marlin AI uses domain-specific SaaS expertise to autonomously triage ...

    Read More »
  • Securing AI Agents in SaaS with Obsidian

    Securing AI Agents in SaaS with Obsidian

    Obsidian Security has launched a new defense system specifically designed to secure AI agents in SaaS environments, addressing the security gaps and cascading threats created by their rapid integration and excessive permissions. The proliferation of AI agents, such as those from Microsoft Copilot...

    Read More »
  • Vorlon Enhances AI Agent Security with Forensics and Response

    Vorlon Enhances AI Agent Security with Forensics and Response

    The rapid adoption of AI agents has created a critical security vulnerability, with 99.4% of organizations reporting a security incident in their SaaS or AI ecosystem last year, and most teams lacking the ability to fully understand or contain breaches due to a structural gap in incident response...

    Read More »
  • Atlassian Jira Scammers Target Trusted Organizations

    Atlassian Jira Scammers Target Trusted Organizations

    A sophisticated phishing campaign exploited Atlassian's Jira platform to send fraudulent emails that bypassed security filters by appearing as legitimate notifications from trusted domains. The attackers used localized content and targeted specific professional groups, leveraging trial accounts t...

    Read More »
  • Neon Cyber Launches Workforce Cybersecurity Platform

    Neon Cyber Launches Workforce Cybersecurity Platform

    Neon Cyber has launched the industry's first Workforce Cybersecurity Platform (WCP), focusing on human-centric threats like phishing and credential misuse to protect users across browsers, SaaS, and enterprise systems. The platform offers AI-driven phishing protection, visibility into shadow IT, ...

    Read More »
  • 6 Overlooked Okta Security Settings You Must Check Now

    6 Overlooked Okta Security Settings You Must Check Now

    Securing identity providers like Okta is critical as they act as central gatekeepers for digital access, with risks arising from misconfigurations and evolving threats. The article outlines six essential Okta security practices, including robust password policies, phishing-resistant MFA, and feat...

    Read More »
  • Salesforce, ServiceNow portals hit by 'City-Forum' data-theft attacks

    Salesforce, ServiceNow portals hit by 'City-Forum' data-theft attacks

    The City-Forum campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow portals to steal sensitive data via unauthenticated guest access, with all attacks traced to a single IP (158.220.87.79) linked to city-forum.com since March 2025. Attackers target Salesforce's legacy Aura a...

    Read More »
  • Shadow AI's Hidden Risks to SaaS Security & Integrations

    Shadow AI's Hidden Risks to SaaS Security & Integrations

    Shadow AI, the unofficial use of AI tools by employees, creates significant security vulnerabilities and data exposure risks within organizations. The threat extends beyond standalone AI apps to embedded AI features in common business software and to exploitable, forgotten integrations like OAuth...

    Read More »
  • 3 Browser Sandbox Threats That Evade Security Tools

    3 Browser Sandbox Threats That Evade Security Tools

    Browsers are the primary target for cyberattacks but are often neglected in security frameworks, as they handle critical tasks yet prioritize performance over advanced threat protection. Key browser threats include credential theft, malicious extensions, and lateral movement, which exploit standa...

    Read More »
  • Luxury Giants Louis Vuitton, Dior, Tiffany Fined $25M for Data Breaches

    Luxury Giants Louis Vuitton, Dior, Tiffany Fined $25M for Data Breaches

    South Korea's Personal Information Protection Commission (PIPC) has fined Louis Vuitton, Christian Dior, and Tiffany a total of $25 million for data breaches that exposed over 5.5 million customers' personal information due to inadequate security on shared cloud platforms. The breaches occurred t...

    Read More »
  • Black Kite Unveils Software Supply Chain Vulnerabilities at Product Level

    Black Kite Unveils Software Supply Chain Vulnerabilities at Product Level

    Black Kite's new Product Analysis module enables security teams to assess software supply chain vulnerabilities at the individual product level, moving beyond traditional vendor evaluations for more granular risk assessment. The module provides precise insights by analyzing downloadable software,...

    Read More »
  • Cisco ASA Zero-Day & Fortra GoAnywhere Under Active Attack

    Cisco ASA Zero-Day & Fortra GoAnywhere Under Active Attack

    A wave of sophisticated cyberattacks is exploiting newly discovered zero-day vulnerabilities in critical enterprise infrastructure, including Cisco's ASA and Fortra's GoAnywhere, posing significant risks to organizational networks and sensitive data. Law firms are increasingly targeted by cybercr...

    Read More »
  • Mirage2FA phishing kit steals Microsoft 365 credentials via HTML smuggling

    Mirage2FA phishing kit steals Microsoft 365 credentials via HTML smuggling

    The Mirage2FA phishing kit targets Microsoft 365 users by using HTML smuggling and obfuscated JavaScript to steal credentials, bypassing multi-factor authentication through fake prompts for authenticator apps and number matching. The attack begins with business-themed email lures containing HTML ...

    Read More »
  • Radware Exposes Critical ChatGPT Zero-Click Vulnerability

    Radware Exposes Critical ChatGPT Zero-Click Vulnerability

    Radware discovered "ShadowLeak," a zero-click vulnerability in ChatGPT's Deep Research agent that autonomously extracts sensitive data from OpenAI's cloud servers without user interaction. The exploit allows attackers to trigger a data breach simply by sending an email, as the AI agent processes ...

    Read More »
  • Vercel Confirms Security Breach

    Vercel Confirms Security Breach

    Vercel confirmed a security breach where a "highly sophisticated" attacker exploited an employee's use of third-party tool Context.ai to access Google Workspace and view non-sensitive environment variables. The company stated no npm packages were compromised, meaning Next.js remains safe, and sen...

    Read More »
  • Secure Your Cloud with cnspec: Open-Source Policy & Security

    Secure Your Cloud with cnspec: Open-Source Policy & Security

    cnspec is an open-source tool that provides unified security and compliance scanning across diverse technologies, identifying vulnerabilities and misconfigurations to prioritize fixes. It supports a wide range of targets including cloud platforms, Kubernetes, containers, SaaS applications, infras...

    Read More »