Tag: saas security
10 articles

Microsoft Copilot Flaw Uncovered Through AI Model Manipulation
Researchers uncovered a concerning vulnerability in Microsoft Copilot, dubbed CoSnitch, which can be exploited with just one click to steal sensitive data without triggering obvious security alerts. The flaw was unusually revealed by Copilot itself during a normal interaction, highlighting the need for organizations to treat AI assistants with greater caution and scrutiny.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft
A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Cyber-Attackers Target Cloud and SaaS Environments With Identity-Based Threats
Cyber attackers have found a clever way to infiltrate cloud and SaaS environments: they exploit trusted identities and legitimate tools, eliminating the need to bypass security controls. By compromising identities and using delegated access, threat actors can wreak havoc without triggering traditional alarms.

Security Teams Must Enforce AI Agent Controls Beyond Visibility
Discovering AI agents across your organization is just the starting line - the real challenge lies in controlling their actions to prevent potential security threats. Simply seeing what's out there isn't enough; it's time to take charge and enforce limits on these active actors.

SaaS Providers Face Trust Crisis After Canvas Breach
A massive breach of the Canvas learning management system has left 275 million users reeling, compromising student records and disrupting learning at over 8,800 institutions worldwide. The shocking incident has sparked a trust crisis for SaaS providers, raising urgent questions about security and data protection.

Enterprises Lose Visibility as AI Adoption Surges
As AI adoption surges in ANZ enterprises, a concerning gap is emerging: over half of organizations lack confidence in their ability to monitor and govern these new technologies, leaving them vulnerable to an expanding attack surface. AI agents and copilots are rolling out faster than security teams can keep up, creating a visibility blind spot that's hard to ignore.

SaaS Breaches Expose Gaps in Enterprise Security Thinking
In a shocking display of vulnerability, ShinyHunters breached Instructure's Canvas platform not once, but twice in a single week, siphoning off a staggering 3.65 terabytes of data from 275 million users across 8,000 institutions. The brazen attacks left hundreds of schools reeling during final exams, forcing Canvas offline and lining the attackers' pockets with a ransom payment.

ShinyHunters Breach Exposes Educational SaaS Canvas
ShinyHunters hackers have claimed responsibility for taking down educational software platform Canvas in a cyberattack that left users offline. The group didn't hold back, giving the developer a scathing "F for security" in their criticism of the breach.

ShinyHunters Breach Educational SaaS Canvas
A recent cyberattack has left Canvas, a popular educational software-as-a-service platform, offline, with hackers group ShinyHunters taking credit for the breach and raising serious concerns about the platform's security. The incident has disrupted learning and left many wondering about the safety of sensitive data.
Malware Disguised as Roblox Cheats Fuels Vercel Breach
Malware masquerading as Roblox cheats sparked a chain reaction, leading to a significant security breach at Vercel and exposing vulnerabilities in modern cloud and SaaS ecosystems. This incident highlights how a seemingly harmless piece of malware can wreak havoc across connected services.