🆕 Device code phishing explained

AppOmni

    SOLUTIONS

    Strategic Initiatives

    SaaS app discovery

    Achieve zero trust

    Reduce threat exposure

    Assess SaaS risk

    Meet compliance goals

    How AppOmni helps

    Threat Detection

    Posture Management

    Third-Party Risk Management

    Secure AI in SaaS

    AI-powered security

    Featured Resources

    AppOmni

    Microsoft 365 Security Handbook

    How to Secure Salesforce: Essential Best Practices to Protect SaaS Data

    Learn how to secure Salesforce
    PRODUCT

    Identify, protect, detect, and respond to SaaS and AI threats

    The AppOmni Platform

    Secure your mission-critical SaaS apps and agents in SaaS

    Marlin AI

    Autonomous correlation and investigations of SaaS findings

    AskOmni

    GenAI SaaS security assistant

    SaaS Compliance

    Get audit-ready without the manual work

    CRITICAL APPS

    Microsoft 365

    Salesforce

    ServiceNow

    Google Workspace

    Workday

    Supported Applications

    Secure what matters, in depth

    MANAGED SERVICES

    Expert SaaS security without added headcount

    AppOmni Scout

    SaaS and agentic AI threat hunting service

    AppOmni Guard

    Expert-led support for SaaS and AI security

    AI SECURITY

    Increase your organization’s confidence to say yes to AI

    Agent Inventory

    View SaaS-native agents and access within their platform

    AgentGuard

    Monitor and quickly act on AI behaviors in real-time

    Featured Resources

    AO In The News
    Marlin AI™, the first autonomous AI-powered SaaS Security engine
    Thumbnail image showcasing the logo for Marlin AI, AppOmni's Autonomous AI-Powered SaaS Security for Investigation and Guided Remediation
    AO Labs
    BodySnatcher (CVE-2025-12420): agentic hijacking vulnerability in ServiceNow
    PARTNERS

    Empowering our technology partners and service providers to deliver advanced SaaS security solutions.

    The Partner Program

    Read the Partner Blog

    Partner Program Login

    Featured Resources

    Partner & Alliances
    AppOmni Is Now Available in All Major Cloud Marketplaces
    AppOmni
    AppOmni Continues to Lead SaaS Security, Ends Fiscal Year with Strong Momentum

    SAAS SECURITY RESOURCES

    A collection of content to level up your SaaS security program.

    Blog

    Learn Hub

    AO Labs

    Press Releases

    Glossary Terms

    Webinars

    Workshops

    Security Handbooks

    How-To eBooks

    Resource Hub

    Featured Resources

    Findings Report

    The State of SaaS Security Report

    The State of SaaS Security Report
    AppOmni

    Salesforce Security Handbook

    Salesforce Security Handbook

    COMPANY

    Safeguarding your SaaS

    About Us

    Who we are, learn our mission

    Customers

    How the world’s leading companies secure their SaaS & AI

    Contact Us

    Get answers on SaaS & AI security

    Join the Team

    Learn about career opportunities at AppOmni

    Newsroom

    AppOmni in the news

    Trust Center

    Protecting your data

    Events

    Meet us in person

    Featured Resources

    AppOmni

    AppOmni Report Uncovers Major Gaps in SaaS Security Preparedness as Breaches Continue to Rise

    Findings Report

    Proven ROI for SaaS Security: Insights From AppOmni Customers

    Request a Demo

The Leader in SaaS Security Threat Research

AppOmni’s cybersecurity expert researchers discovers, analyzes, and discloses SaaS risks and vulnerabilities to strengthen the AppOmni platform and promote SaaS security best practices.

  • An image of hands typing on a keyboard while icons of threat detection show as an overlay
    AO Labs, Blog

    Detecting ShinyHunters/UNC6040 Vishing Campaigns in Salesforce OAuth Attacks

    Spot UNC6040 vishing attacks, secure OAuth apps, boost SaaS security with AppOmni’s Threat Detection.

  • AO Labs, Blog

    Post-Incident CRM Forensics: Why Deploying AppOmni Is a Best Practice

    OAuth abuse exposes SaaS data. AppOmni’s threat detection and security posture management shut it down.

  • Image of a warning alert symbol colored blue
    AO Labs, Blog

    Low-Code, High Stakes: Why Security Can’t Be an Afterthought for Customers Using Salesforce Industry Clouds

    New research reveals critical security flaws in Salesforce industry clouds. Discover the risks and how to protect your organization now.

  • A mockup of the research report from AppOmni reviewing Salesforce industry clouds' attack vectors
    AO Labs

    Salesforce Industry Clouds: 0-days and Exploitable Misconfigs

    AppOmni’s latest research reveals 20+ OmniStudio security flaws, including 5 CVEs affecting Salesforce industry clouds. Learn how misconfigurations expose sensitive data and how to secure your org.

  • AO Labs, Blog

    Microsoft Power Pages: Data Exposure Reviewed

    Learn about a data exposure risk in Microsoft Power Pages due to misconfigured access controls, highlighting the need for better security and monitoring.

  • AO Labs, Blog

    Enterprise ServiceNow Knowledge Bases at Risk: Extensive Data Exposures Uncovered

    Read the blog to learn about ServiceNow’s Knowledge Base data exposure risks and how to mitigate these issues.

  • AO Labs, Blog

    Potential Widespread Data Exposure Analysis: Oracle NetSuite

    Read the blog for an analysis on the potential data exposure of Oracle NetSuite with a thorough understanding of NetSuite access control model, basic SuiteCommerce concepts and more.

  • Salesforce Community Cloud Scanner | AppOmni
    AO Labs

    Salesforce Community Cloud Scanner

    Learn how to secure your Salesforce Community websites from data exposure risks with support from the AO Labs threat research team.

  • Blog

    SaaS Risks in Healthcare: Anatomy of a Data Exposure at the HSE

    SaaS Security Engineer Aaron Costello explains how to handle sensitive data in SaaS apps, as learned from misconfiguration in Ireland’s vaccination portal (HSE).

  • Blog

    Balancing Act: Navigating the Advantages and Risks of ServiceNow’s New Security Attributes

    Security Attributes offer an alternative method for access control via role definitions, designed to be human-readable and offer detailed auditing and logging.

  • AO Labs, Blog

    A Technical Analysis and Lessons From The Recent Service Now Misconfiguration Risks

    Learn more about the ServiceNow updates to mitigate ACL misconfiguration risks and how to avoid regressing your organization’s data security posture moving forward.

  • Full SSO Compromise - research by AppOmni Labs
    AO Labs, Blog

    Admin Account Takeover Leads to Full SSO Compromise During AO Labs Research

    Discover how AO Labs achieved read/write access of over 200K users & staff on a leading service provider’s Okta instance.

  • illustration of data exposure, leaked data
    AO Labs, Blog

    Salesforce Misuse of Platform Cache Leads to Widespread Data Exposure

    Learn how Salesforce Platform Cache misuse is causing information disclosure in over 80% of implementations handling sensitive data.

  • SaaS Related Attacks Tracked by AppOmni Labs
    AO Labs, Blog

    AO Labs Notes An Over 300% Increase in SaaS Attacks

    Learn about the significant upward trend in threat activity on Salesforce Community Sites targeting customer-side misconfigurations.

  • AO Labs, Blog

    Major Security Misconfiguration Impacting ServiceNow and Other SaaS Instances Discovered

    Major security misconfiguration impacting ServiceNow and other SaaS instances discovered nearly 70% of tested instances are leaking data.

  • AO Labs, Blog

    Avoid Salesforce Security Vulnerabilities When Building Custom Lightning Components in Apex

    Lightning Components offer an unlimited amount of functionality. But security vulnerabilities may be introduced within Apex code exploited by a malicious actor.

  • image illustrating third-party app risks in SaaS environments
    AO Labs, Blog

    Third-Party Risk in Salesforce Named Credentials

    This article provides an overview of Named Credentials, a feature introduced by Salesforce in the Spring ’15 release to combat the issue of hardcoded credentials within an organization’s Apex codebase.

  • AO Labs, Blog

    Understanding Salesforce Flows and Common Security Risks

    Discover how Salesforce Flow Builder simplifies process automation and the key security risks and permission pitfalls to address for safe implementation.

  • Salesforce Lightning Components: A Treatise on Apex Security
    AO Labs, Blog

    Salesforce Lightning Components

    Get to know the architecture behind Lightning Aura components and learn how a call to an Apex method with parameters.

SaaS Security RoundUp

Company
In the News
About Us
Platform
Careers
Partners
Contact Us
Resources
Blog
Learn Hub
Glossary
AO Labs
Security Handbooks
Success Stories
Help Center
Secured Apps
Microsoft 365
Salesforce
ServiceNow
Google Workspace
Workday
Supported Apps
Use Cases
SaaS Discovery
Config Management
Data Exposure
Threat Detection
Connected Apps
Compliance
  • LinkedIn
  • YouTube
  • X

Privacy Policy | Terms of Service | Professional Services Terms and Conditions | Service Level Agreement | SaaS Terms & Conditions | Product Privacy Data Sheet | AO Labs Responsible Disclosure Policy

© 2026 AppOmni. All rights reserved.