SAP AI Core Vulnerabilities Expose Customer Data to Cyber Attacks
ID: 6b135e6c-751f-5bfd-91da-68f65c49821c
STIX ID: report--6b135e6c-751f-5bfd-91da-68f65c49821c
Feed Name: The Hacker News
Researchers disclosed five vulnerabilities in SAP AI Core ("SAPwned") that could let attackers access customer data and cloud credentials (AWS, Azure, SAP HANA), modify Docker/container artifacts, and escalate to Kubernetes cluster admin — creating a realistic supply-chain and cross-tenant compromise risk; the issues were responsibly disclosed on 2024-01-25 and patched by SAP on 2024-05-15. The report additionally highlights the broader ecosystem risk from criminal groups like NullBulge that target AI and gaming services using info-stealers, RATs, and ransomware payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
