SaaS Apps Present an Abbreviated Kill Chain for Attackers
ID: 460ed912-6d66-58d9-b524-018d96021a32
STIX ID: report--460ed912-6d66-58d9-b524-018d96021a32
Feed Name: Dark Reading
Researchers at AppOmni presented at Black Hat USA 2024 that widespread SaaS adoption has shortened the cyber kill chain: attackers commonly gain access through compromised identity providers (via infostealers, credential stuffing, brute force, or purchased credentials) and can immediately access, modify, and exfiltrate data across many applications without traditional lateral movement or persistence. The analysis of billions of SaaS audit logs highlights frequent attacks against O365 and other services, demonstrates rapid 'smash-and-grab' exfiltration scenarios, and recommends improved SaaS visibility, hardened IdP configurations, MFA/hardware tokens, and zero-trust access models.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
