New research drives security enhancements for Salesforce industry clouds
AppOmni
  • Attend an Event
  • Trust Center
  • Contact Us

    Solutions

    by Customer Initiatives


    SaaS Risk Assessment
    Threat Exposure Management
    Posture Management
    Zero Trust for SaaS

    by Industries


    Financial Services
    Healthcare & Life Sciences
    Technology
    Legal
    Public Sector

    for Critical Applications


    Microsoft 365
    Salesforce
    ServiceNow
    Google Workspace
    Workday

    Product

    Identify, Protect, Detect, and Respond to SaaS Threats

    The AppOmni Platform

    SaaS Discovery
    Configuration Management
    Third Party Risk
    Threat Detection
    Compliance
    AskOmni – SaaS AI Companion
    Supported Applications

    Featured Resources

    AppOmni
    Microsoft 365 Security Handbook
    AppOmni
    Simplify SaaS Security: How Posture Scoring Empowers Teams to Optimize SSPM

    Customers

    Trusted by the most innovative companies across the globe.


    University of Cincinnati
    DLA Piper
    Spencer Fane
    Rightmove
    BluOcean
    More Success Stories

    Featured Resources

    AppOmni
    How the University of Cincinnati gained full visibility & control over SaaS security
    A photo of the University of Cincinnati with a blue overlay and the logo for the university in white on top.
    AppOmni
    How Rightmove secures and optimizes its expanding SaaS estate with AppOmni
    Rightmove + Peritus Co Branded Case Study Graphic

    Partners

    Empowering our technology partners and service providers to deliver advanced SaaS security solutions.

    The Partner Program

    Read the Partner Blog
    Partner Portal Login

    Featured Resources

    AppOmni
    CRN Recognizes SaaS Security Leader, AppOmni for Channel Success
    AppOmni
    AppOmni Continues to Lead SaaS Security, Ends Fiscal Year with Strong Momentum

    SaaS Security Resources

    A collection of content to level up your SaaS security program.

    Browse Resources

    Blog
    Webinars
    In The News
    Workshops
    eBooks & Guides
    AO Labs
    Glossary Terms
    What is SaaS Security?
    Security Handbooks
    Press Releases

    Featured Resources

    AppOmni
    The Definitive Guide to SaaS Security eBook
    The Definitive Guide to SaaS Security eBook
    AppOmni
    Simplifying SaaS Security with the Power of GenAI
    Simplifying SaaS Security with the Power of GenAI
    Request a Demo

The Leader in SaaS Security Threat Research

AppOmni’s cybersecurity expert researchers discovers, analyzes, and discloses SaaS risks and vulnerabilities to strengthen the AppOmni platform and promote SaaS security best practices.

  • A mockup of the research report from AppOmni reviewing Salesforce industry clouds' attack vectors
    AO Labs

    New Research on Salesforce Industry Clouds: 0-days, Insecure Defaults, and Exploitable Misconfigurations

    AppOmni’s latest research reveals 20+ OmniStudio security flaws, including 5 CVEs affecting Salesforce industry clouds. Learn how misconfigurations expose sensitive data and how to secure your org.

  • Image of a warning alert symbol colored blue
    Blog

    Low-Code, High Stakes: Why Security Can’t Be an Afterthought for Customers Using Salesforce Industry Clouds

    New research reveals critical security flaws in Salesforce industry clouds. Discover the risks and how to protect your organization now.

  • AO Labs, Blog

    Microsoft Power Pages: Data Exposure Reviewed

    Learn about a data exposure risk in Microsoft Power Pages due to misconfigured access controls, highlighting the need for better security and monitoring.

  • AO Labs, Blog

    Enterprise ServiceNow Knowledge Bases at Risk: Extensive Data Exposures Uncovered

    Read the blog to learn about ServiceNow’s Knowledge Base data exposure risks and how to mitigate these issues.

  • AO Labs, Blog

    Potential Widespread Data Exposure Analysis: Oracle NetSuite

    Read the blog for an analysis on the potential data exposure of Oracle NetSuite with a thorough understanding of NetSuite access control model, basic SuiteCommerce concepts and more.

  • Salesforce Community Cloud Scanner | AppOmni
    AO Labs, SaaS Resources

    Salesforce Community Cloud Scanner

    Learn how to secure your Salesforce Community websites from data exposure risks with support from the AO Labs threat research team.

  • Blog

    SaaS Risks in Healthcare: Anatomy of a Data Exposure at the HSE

    SaaS Security Engineer Aaron Costello explains how to handle sensitive data in SaaS apps, as learned from misconfiguration in Ireland’s vaccination portal (HSE).

  • Blog

    Balancing Act: Navigating the Advantages and Risks of ServiceNow’s New Security Attributes

    Security Attributes offer an alternative method for access control via role definitions, designed to be human-readable and offer detailed auditing and logging.

  • A Technical Analysis and Lessons From The Recent Service Now Misconfiguration Risks
    AO Labs, Blog

    A Technical Analysis and Lessons From The Recent Service Now Misconfiguration Risks

    Learn more about the ServiceNow updates to mitigate ACL misconfiguration risks and how to avoid regressing your organization’s data security posture moving forward.

  • Full SSO Compromise - research by AppOmni Labs
    AO Labs, Blog

    Admin Account Takeover Leads to Full SSO Compromise During AO Labs Research

    Discover how AO Labs achieved read/write access of over 200K users & staff on a leading service provider’s Okta instance.

  • Salesforce Data Exposure
    AO Labs, Blog

    Salesforce Misuse of Platform Cache Leads to Widespread Data Exposure

    Learn how Salesforce Platform Cache misuse is causing information disclosure in over 80% of implementations handling sensitive data.

  • SaaS Related Attacks Tracked by AppOmni Labs
    AO Labs, Blog

    AO Labs Notes An Over 300% Increase in SaaS Attacks

    Learn about the significant upward trend in threat activity on Salesforce Community Sites targeting customer-side misconfigurations.

  • AO Labs, Blog

    Major Security Misconfiguration Impacting ServiceNow and Other SaaS Instances Discovered

    Major security misconfiguration impacting ServiceNow and other SaaS instances discovered nearly 70% of tested instances are leaking data.

  • AO Labs, Blog

    Avoid Salesforce Security Vulnerabilities When Building Custom Lightning Components in Apex

    Lightning Components offer an unlimited amount of functionality. But security vulnerabilities may be introduced within Apex code exploited by a malicious actor.

  • AO Labs, Blog

    Third-Party Risk in Salesforce Named Credentials

    This article provides an overview of Named Credentials, a feature introduced by Salesforce in the Spring ’15 release to combat the issue of hardcoded credentials within an organization’s Apex codebase.

  • AO Labs, Blog

    Understanding Salesforce Flows and Common Security Risks

    Discover how Salesforce Flow Builder simplifies process automation and the key security risks and permission pitfalls to address for safe implementation.

  • Salesforce Lightning Components: A Treatise on Apex Security
    AO Labs, Blog

    Salesforce Lightning Components

    Get to know the architecture behind Lightning Aura components and learn how a call to an Apex method with parameters.

SaaS Security RoundUp

Company
In the News
About Us
Platform
Careers
Partners
Contact Us
Resources
Blog
Glossary
AO Labs
Security Handbooks
Success Stories
Help Center
Secured Apps
Microsoft 365
Salesforce
ServiceNow
Workday
Supported Apps
Use Cases
Configuration
Data Exposure
Threat Detection
Connected Apps
Compliance
  • LinkedIn
  • YouTube
  • X

Privacy Policy | Terms of Service | Professional Services Terms and Conditions | Service Level Agreement | SaaS Terms & Conditions | Product Privacy Data Sheet | AO Labs Responsible Disclosure Policy

© 2025 AppOmni. All rights reserved.