Astonishing research done by @tincho_508, brings up 3 new critical/high bugs on SAP systems: CVE-2022-22536/22532/22533. CISA alert included: https://t.co/U6x3WgHyAZ
It affects a wide-range of products. Check out the complete documentation of #ICMAD:
https://t.co/I5x6jMH73Y
If you are interested in modern WEB Exploitation techniques, don’t miss my @defcon talk “Response Smuggling - Pwning HTTP/1.1 Connections”.
I will explain new attacks that could be used to compromise vendors as big as Google! 😉
https://t.co/Ms0FgHqFgD
Checkout the latest advisories of the Onapsis team! https://t.co/HKKNW2ZiJe
From now on, you'll find the information of all our reported and patched vulnerabilities in this repository.
Check out DarkReading's interview and coverage on the recent threat intelligence findings released by SAP, DHS CISA and Onapsis.
"Analysis of threat activity in mission-critical environments prompts CISA advisory urging SAP custo…https://t.co/CeRBQ0z4oX https://t.co/HHT0gQYe0Q
It's #PatchTuesday and Onapsis has you covered with the vulns and patches you should know about to keep your organization protected.
March 2021 Summary—18 new and updated #SAP security patches released https://t.co/hEUU2YQhB6
If you are somehow related to SAP systems, you should be aware of this. New public exploits of a vulnerability found by @_1ggy and myself last year: https://t.co/mZYouS2YCx
We have talked about this (and its remediation) at Black Hat 2020, hopefully this bug is not new for you!
And the 2020 ends with a new CVSS 10 bug in SAP reported by @idfavro affecting SAP JAVA Netweaver. Amazing and super interesting finding.
Behind that one, an 8.5 CVSS bug reported by @G0nz4RE and myself affecting SolMan!
More info: https://t.co/DYjRasi2F2
If you are running mission-critical cloud or on-prem SAP applications, you need to pay attention to this patch day.
Our Research Labs partnered with SAP again to mitigate two highly-critical zero-day vulnerabilities in SAP Solution Manager. If this appli…https://t.co/AK0kT87SYY
NEW blog post analysis for November SAP Patch Day: SAP Solution Manager Affected Again by Two Serious Vulnerabilities
https://t.co/1dtcHcznVX #onapsis#sapsecurity#solman#sap
Tommorow is our talk at @RedTeamVillage_ ! Together with @_1ggy we will show how we found a way to root every SAP system of the landscape. Don't miss it!
As a bonus: a cool trick developed while doing a pentest.. See you there!
https://t.co/NQDR5KEzqz
"... And this is how an attacker may become root in a Company’s Software Servers" by @lmkalg & @_1ggy from @onapsis at #ekoparty 2020 🙌🏼
Watch 👉🏼 https://t.co/6lUveIBCvO
#eko2020#pwndemic
Onapsis is launching support for Salesforce and SuccessFactors. With this latest edition to The Onapsis Platform, customers can quickly discover, assess, prioritize and eliminate application misconfigurations, vulnerabilities and malicious activity.
https://t.co/liNEQLWRy4
Onapsis has led an industry-wide collaboration that uncovered novel insights on the risk of RECON-like vulnerabilities and mission-critical applications. Read these 10 new articles with surprising new data and perspectives from observed real-world attacks…https://t.co/KIntI71u29
A great and comprehensive article. Recommended especially because it provides information to make the best decision. Very good work @G0nz4RE !
#SAP#Security#vulnerabilities