Resource Hub
A collection of our latest articles, videos, news, and more.
-
Mapping TTPs to SaaS Supply Chain Attacks: Recent SaaS Breaches
If you’re still thinking of SaaS supply chain attacks as tomorrow’s problem, think again. The biggest breaches in the last year didn’t…
-
Setting a SaaS Security Baseline: Why the CSA’s New SaaS Security Capability Framework (SSCF) Matters
Explore the CSA’s new SaaS Security Capability Framework (SSCF) and how it helps enterprises reduce risk, standardize controls, and stop SaaS attacks.
-
From OAuth Abuse to Data Theft: How AppOmni + Cribl Block UNC6395-Style Attacks
OAuth abuse detection thwarts SaaS supply chain attacks like UNC6395; AppOmni and Cribl boost SaaS threat visibility.
-
How New Supply Chain Attacks Challenge SaaS Security: Lessons from UNC6395 and UNC6040 (ShinyHunters)
SaaS supply chain attacks exploit SaaS-to-SaaS connections using stolen OAuth tokens. Get practical steps to reduce your risk and protect business data.
-
Cloudflare joins list of Salesforce attack victims, provides detailed timeline
Cory Michal, SaaS security expert and CSO at AppOmni, applauds the clarity put forth by the corporate world’s favored network and security…
-
Global asset management firm achieves perfect SaaS audit with AppOmni
AppOmni empowers a global asset management firm with perfect SaaS audit, full visibility, and complete compliance.
-
Salesloft Drift Attacks Exposed Zscaler Customer Data
“Unlike user sessions, OAuth tokens often don’t expire, creating long-term exposure in the event of an OAuth breach,” said SaaS security platform AppOmni.
-
Palo Alto Networks, Zscaler, Cloudflare hit by the latest data breach
Cory Michal, CSO at SaaS app security vendor AppOmni, applauded the way Cloudflare described its role.
-
Breach of Salesloft Drift integration exposes data at Cloudflare, Zscaler and Palo Alto Networks
The breaches of Zscaler and Palo Alto Networks “are particularly concerning because they raise the stakes well beyond typical SaaS compromises…” said…
-
Warning issued to Salesforce customers after hackers stole Salesloft Drift data
“The attacker didn’t need to break Salesforce itself, they abused OAuth tokens from a widely used and trusted third-party integration to gain…