More Than The Sum of its Parts: Combining EASM and Pentesting
ID: 53e3c39b-49d4-56cb-9bd2-d6a7093b8887
STIX ID: report--53e3c39b-49d4-56cb-9bd2-d6a7093b8887
Feed Name: Outpost24 Blog
In late April 2025 SAP issued an emergency patch for CVE-2025-31324 in NetWeaver Visual Composer after reports that the zero-day allowed unauthenticated file uploads (via /developmentserver/metadatauploader), had been exploited since February/March to drop webshells into public directories, and resulted in hundreds to thousands of compromised systems; subsequent months saw rising ransomware campaigns and chained exploits (e.g., CVE-2025-42999). The author argues that while EASM helps discover externally exposed assets, it cannot reliably detect prior intrusions or logic flaws, and recommends integrating External Attack Surface Management with penetration testing (including PTaaS) and Digital Risk Protection to close gaps and better respond to fast-moving zero-day exploitation and attack chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
