home.social

#saassecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #saassecurity, aggregated by home.social.

fetched live
  1. SaaS Providers Face Trust Crisis After Canvas Breach

    A massive breach of the Canvas learning management system has left 275 million users reeling, compromising student records and disrupting learning at over 8,800 institutions worldwide. The shocking incident has sparked a trust crisis for SaaS providers, raising urgent questions about security and data protection.

    osintsights.com/saas-providers

    #SaasSecurity #LearningManagementSystem #CanvasBreach #Ransomware #DataBreach

  2. SaaS Breaches Expose Gaps in Enterprise Security Thinking

    In a shocking display of vulnerability, ShinyHunters breached Instructure's Canvas platform not once, but twice in a single week, siphoning off a staggering 3.65 terabytes of data from 275 million users across 8,000 institutions. The brazen attacks left hundreds of schools reeling during final exams, forcing Canvas offline and lining the…

    osintsights.com/saas-breaches-

    #SaasSecurity #Shinyhunters #DataBreach #Ransomware #EducationSector

  3. Malware Disguised as Roblox Cheats Fuels Vercel Breach

    Malware masquerading as Roblox cheats sparked a chain reaction, leading to a significant security breach at Vercel and exposing vulnerabilities in modern cloud and SaaS ecosystems. This incident highlights how a seemingly harmless piece of malware can wreak havoc across connected services.

    osintsights.com/malware-disgui

    #MalwareOperations #Roblox #Vercel #CloudSecurity #SaasSecurity

  4. Malicious Outlook add-in “AgreeToSteal” hijacked a deleted subdomain.

    Result:
    • 4,000+ accounts compromised
    • Fake Microsoft login inside Outlook
    • Credit cards + banking data stolen
    Manifest validated once. External URL later hijacked.
    Architectural gap exposed.

    technadu.com/malicious-outlook

    #InfoSec #Microsoft365 #Phishing #SaaSSecurity

  5. Researchers have disclosed a coordinated campaign involving malicious Chrome extensions impersonating enterprise HR and ERP platforms, including Workday and NetSuite.

    The extensions demonstrated capabilities such as:
    - Continuous cookie exfiltration
    - Blocking of security administration pages via DOM manipulation
    - Session hijacking through injected authentication states

    The activity highlights persistent risks within browser extension ecosystems, especially when tools present themselves as productivity enhancers.

    What detection or control mechanisms do you rely on for extension risk management?

    Source: thehackernews.com/2026/01/five

    Engage in the discussion and follow @technadu for vendor-neutral cybersecurity reporting.

    #InfoSec #ThreatResearch #BrowserExtensions #SaaSSecurity #AccountTakeover #TechNadu

  6. Salesforce is investigating a data theft campaign tied to a compromised Gainsight integration. OAuth token theft - not a Salesforce platform flaw - enabled unauthorized access to certain customer environments.

    ShinyHunters claim “almost 1,000” victim organizations and additional access to hundreds of Salesforce instances linked to the earlier Salesloft Drift incident.

    Full details:
    technadu.com/salesforce-data-s

    Follow us for more SaaS ecosystem security updates.

    #CyberSecurity #Salesforce #OAuth #SaaSSecurity #ShinyHunters

  7. Adam Koblentz from RevealSecurity shares why context - not anomalies - drives SaaS threat detection.

    Lessons from the Salesloft Drift breach show why raw app logs aren’t enough without normalization and business semantics.

    Read full interview:
    technadu.com/context-is-key-wh

    #SaaSSecurity #UEBA #IdentityAnalytics #ZeroTrust

  8. Gary Brickhouse (GuidePointSec CISO) told TechNadu:

    “Without funding tied to identity controls like anomaly detection, the investment in your castle walls won’t matter when a threat actor walks through your front door.”

    Read full interview 👉 technadu.com/when-identity-bli

    #IdentitySecurity #ZeroTrust #SaaSSecurity

  9. Gary Brickhouse (GuidePointSec CISO) told TechNadu:

    “Without funding tied to identity controls like anomaly detection, the investment in your castle walls won’t matter when a threat actor walks through your front door.”

    Read full interview 👉 technadu.com/when-identity-bli

    #IdentitySecurity #ZeroTrust #SaaSSecurity

  10. One weak app integration exposed some of the world’s largest companies, from Cloudflare to Palo Alto Networks.

    Our latest blog breaks down the Salesforce–Drift breach: how attackers turned insecure OAuth tokens into skeleton keys, why the headlines were misleading, and — most importantly — what CISOs and IT leaders must do to defend against the next SaaS supply chain attack.

    👉 Read the full article: lmgsecurity.com/connected-app-

    #Cybersecurity #SupplyChainRisk #SaaSSecurity #LMGSecurity

  11. Salesforce breaches by ShinyHunters are shaking up the tech world—major companies like Google and Cloudflare caught off guard by sneaky token hacks. How safe is your data in the cloud? Read more to find out.

    thedefendopsdiaries.com/naviga

    #salesforcebreach
    #shinyhunters
    #saassecurity
    #cloudsecurity
    #cyberthreats

  12. Microsoft 365 credential theft is evolving—and AI tools like Microsoft Co-Pilot are becoming attackers' latest weapons!

    Watch our new, 4-minute video, to learn how attackers use #CoPilot for rapid reconnaissance and fraud, see real-world phishing examples targeting Microsoft 365, Adobe, and DocuSign, and understand why SSO and OAuth vulnerabilities significantly amplify credential risks.

    We'll also share essential steps to protect your organization! youtu.be/zaBwxy1Gjhc

    #Microsoft365 #CredentialTheft #Cybersecurity #CoPilotSecurity #Phishing #ZeroTrust #AIThreats #SaaSsecurity #DocuSignPhishing #M365 #Cyberaware #InfoSec #CloudSecurity

  13. What is SaaS Security? Benefits, Challenges, and Best Practices - In today’s world, technology dominates everything from the simplest to the most co... - readwrite.com/what-is-saas-sec #dataandsecurity #saassecurity

  14. AppOmni raises $40M for tools to secure enterprise SaaS apps - Enterprises are adopting an ever-wider range of SaaS applications to work and inte... - feedproxy.google.com/~r/Techcr #saassecurity #enterprise #security #appomni #saas