Tag: saas
-
Penetration Testing Cost for Small SaaS Startups
Ask three vendors for a pentest quote and you will likely get three numbers that do not seem to be describing the same service. That is not a coincidence, it is the actual state of penetration testing cost for small SaaS startups right now, and it is worth breaking down honestly rather than papering over.…
-
Cloud and SaaS Environments Now Top Targets for Attackers
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/
-
Model Context Protocol: Can it be the next carrier of AI Security Risks?
Enterprises are racing to plug Large Language Models (LLMs) into their internal systems CRMs, ticketing tools, code repositories, databases, and SaaS platforms. The Model Context Protocol (MCP) has emerged as the leading standard for this integration. It gives AI models a uniform way to discover and call external tools, read files, and pull live context……
-
Why SSO and data governance should be planned together in enterprise SaaS
Learn how SSO, SCIM, RBAC, MFA, and audit logs strengthen enterprise data governance, improve data security, and support trusted data management. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-sso-and-data-governance-should-be-planned-together-in-enterprise-saas/
-
Enterprise Security Checklist for New SaaS Companies: From Domain Registration to Single Sign-On
Learn the essential security practices every SaaS startup should implement, including SSO, SCIM, MFA, email authentication, audit logs, and continuous monitoring. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/enterprise-security-checklist-for-new-saas-companies-from-domain-registration-to-single-sign-on/
-
20 Key Terms You Should Know About SaaS Finance
In this blog post, we’ll explore 20 of the most important terms you should know about SaaS finance, including Monthly Recurring Revenue (MRR), Annual Recu First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/20-key-terms-you-should-know-about-saas-finance/
-
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform…
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…
-
Internet-Intelligence und Attack-Surface-Management als Basis für Exposure-Management
Die Angriffsfläche von Unternehmen wächst kontinuierlich. Cloud-Dienste, SaaS-Anwendungen, IoT-Sensoren, hybride Infrastrukturen und Remote-Work sorgen dafür, dass immer mehr Systeme direkt über das Internet erreichbar sind. Eine umfassende Transparenz mit Exposure-Management wird damit zu einer zentralen Voraussetzung für wirksame Cybersecurity. Externe Angriffspunkte bilden den Ausgangspunkt vieler erfolgreicher Angriffe. Fehlkonfigurationen, Schatten-IT, unbeabsichtigter Remote-Access und im Internet sichtbare…
-
Zero Trust: Warum das Vertrauen im Firmennetz zum Sicherheitsrisiko geworden ist
Management Summary Zero Trust ist ein strategischer Sicherheitsansatz, der implizites Vertrauen im Firmennetz durch kontinuierliche Prüfung von Identität, Gerät, Kontext und Berechtigung ersetzt. Verteilte Arbeit, Cloud- und SaaS-Nutzung sowie externe Dienstleister machen klassische Perimeter-Sicherheit zunehmend unwirksam. Moderne Angriffe zielen verstärkt auf Identitäten, gestohlene Zugangsdaten, laterale Bewegung und Schwachstellen in der Lieferkette. Zentrale Bausteine sind starke……
-
OAuth, guest accounts, and weak MFA drive SaaS risk
Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/saas-environments-security-risks-report/
-
The Elephants in the Technology Room – Part 4
Why IT and Security Teams Can No Longer See What They’re Supposed to Protect Shadow IT has evolved into shadow SaaS, shadow AI, shadow data and autonomous agents that operate beyond security’s view. Traditional governance models can no longer keep pace. Organizations must transition from blocking technology to making its use visible, monitored and data-controlled.…
-
Infinite Campus: Salesforce Breach Exposed 137,000 Staff Records
Infinite Campus says a Salesforce breach exposed data tied to 137,000 school staff accounts, raising phishing and SaaS security concerns. The post Infinite Campus: Salesforce Breach Exposed 137,000 Staff Records appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-infinite-campus-salesforce-breach-school-staff-data/
-
Infinite Campus Incident Exposes Data From 137,000 School Staff Accounts
A breach at Infinite Campus exposed data from 137,000 school staff accounts, highlighting SaaS security risks in education. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/infinite-campus-incident-exposes-data-from-137000-school-staff-accounts/
-
MSPs get a faster way to secure SaaS environments
First seen on scworld.com Jump to article: www.scworld.com/news/msps-get-a-faster-way-to-secure-saas-environments
-
Hackers Exploit Claude Code MCP Traffic to Hijack OAuth Authentication Tokens
Threat researchers have uncovered a novel man-in-the-middle (MitM) attack chain targeting Anthropic’s Claude Code ecosystem, where adversaries hijack Model Context Protocol (MCP) traffic to steal OAuth authentication tokens and persist access to enterprise SaaS platforms. The technique, detailed by Mitiga, abuses weak protections around the local Claude Code configuration file (~/.claude.json), effectively turning it into…
-
Zscaler Targets AI Identity Risk With Symmetry Acquisition
Startup Symmetry Systems Maps Relationships Across AI, SaaS and Cloud Assets. Zscaler plans to acquire San Francisco-based Symmetry Systems to unify visibility across AI models, identities, applications and datasets, helping enterprises track AI lineage, govern agentic identities and enforce granular zero trust controls across cloud and SaaS environments. First seen on govinfosecurity.com Jump to article:…
-
The Canvas breach proved that prevention is no longer enough
Cybercriminals brought down the most widely used learning platform in North America. The Canvas breach is a blueprint for how SaaS attacks now work, and a warning about how unprepared most organizations still are. First seen on cyberscoop.com Jump to article: cyberscoop.com/canvas-breach-saas-security-identity-governance-op-ed/
-
Warum eingebaute KI-Leitplanken für Agentic-AI nicht ausreichen
KI-Agenten entwickeln sich rasant zu zentralen Werkzeugen der Automatisierung. Um ihre Aufgaben erfüllen zu können, benötigen sie umfangreiche Zugriffsrechte auf Tools, Datenbanken, SaaS-Anwendungen und das Internet. Ein aktueller Bericht unserer Okta Threat Intelligence warnt nun davor, diesen Systemen unreguliert die Schlüssel zum Stadttor wie Anmeldedaten, API-Schlüssel, persönliche Access-Tokens und OAuth-Tokens zu überreichen. Jüngste […] First…
-
Veeam warnt nach Cyberangriff auf Canvas vor unterschätzten SaaS-Risiken
Entscheidend bleibt die Fähigkeit von Unternehmen, Daten unabhängig wiederherstellen und den Geschäftsbetrieb auch nach einem Sicherheitsvorfall schnell fortsetzen zu können. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/veeam-warnt-nach-cyberangriff-auf-canvas-vor-unterschaetzten-saas-risiken/a45086/
-
Hackerangriff auf Lernplattform Canvas
Am vergangenen Freitag wurde die bekannte Lernplattform Canvas zum Ziel eines Angriffs der Hackergruppe <>, die bereits mit ihrer Attacke auf den bekannten Spieleentwickler Rockstar Games auf sich aufmerksam machten. Zwei Sicherheitsexperten von Veeam Software ordnen diesen Vorfall ein und zeigen auf, wie Unternehmen SaaS-Tools wie Canvas absichern können und sollten. Dave Russell, SVP and…
-
AI security is repeating endpoint security’s biggest mistake
Tags: access, ai, api, automation, business, control, data, detection, edr, endpoint, governance, incident response, injection, LLM, monitoring, open-source, radius, risk, saas, sbom, soc, strategy, technology, threat, tool, updateMost AI security is still at the posture phase: Look at where most organizations are with AI security today. Model cards, AI-specific SBOMs, input and output filters, prompt injection guardrails and access controls around model APIs. These are valuable controls, but they reflect a posture-based approach. To truly enhance security, organizations must recognize the importance…
-
WatchGuard Strengthens Cloud Detection With Perimeters Buy
WatchGuard Aims to Reduce Alert Fatigue Through Telemetry Correlation. WatchGuard acquired SaaS security startup Perimeters to strengthen cloud detection and response capabilities spanning identity threat detection, cloud posture management and shadow IT discovery as enterprises face escalating attacks targeting cloud applications and distributed environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/watchguard-strengthens-cloud-detection-perimeters-buy-a-31630
-
Omada Identity stellt mit <> eigene Private-Cloud vor
Omada Identity stellt ‘Omada Identity Cloud Private” für regulierte Unternehmen und Behörden vor. Die neue Bereitstellungsoption bietet regulierten Unternehmen und Regierungsorganisationen die gesamte Omada-Identity-Cloud-Plattform innerhalb ihres eigenen Microsoft-Azure-Tenants. Sie beseitigt damit den Kompromiss zwischen Cloud-nativer IGA und der Tenant-Eigentümerschaft, die ihre Prüfer, Aufsichtsbehörden und Risiko-Analysten erwarten. Kunden haben nun drei Möglichkeiten, Omada-Identity-Cloud zu nutzen: Multi-Tenant-SaaS,…
-
ESecurity-Spezialist Seppmail beruft neuen CEO und stärkt Fokus auf ESecurity und Data-Sovereignty
Seppmail, ein führender Anbieter von Lösungen für sichere E-Mail-Kommunikation, startet mit einem neuen CEO in die nächste Wachstumsphase. Zum 15. April 2026 hat Marcus Zeidler die Position des Chief Executive Officer übernommen und tritt damit die Nachfolge von Gründer Stefan Klein an. Gemeinsam mit LEA Partners, einem führenden Partner für B2B-SaaS-Unternehmen, wird Seppmail den eingeschlagenen…
-
BlueVoyant Prepares SaaS Push Under New CEO John Hernandez
BlueVoyant Seeks to Expand Beyond MDR Clients Into Firms With Mature In-House SOCs. BlueVoyant named John Hernandez – the former leader of Quest’s Microsoft security business – as its next CEO to drive an agentic AI SaaS platform that expands the vendor beyond managed services and helps customers accelerate detection, response and supply-chain risk management.…
-
AI Security vs AI Governance Explained
Understand the difference between AI security and AI governance and why both fail without identity and SaaS control. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/05/ai-security-vs-ai-governance-explained/
-
SaaS Identity Is the New Security Perimeter
Learn why SaaS identity, not the network, is now the true security perimeter in AI-driven environments. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/05/saas-identity-is-the-new-security-perimeter/

