
CISO’s 2023 Planning Guide for ERP Applications
CISO’s 2023 Planning Guide for ERP Applications maaya.alagappan Mon, 01/23/2023 - 15:48 ERP systems, such as SAP and Oracle applications, run essential business functions and contain an organization’s most valuable data from HR and customer information to intellectual property and company financials. Despite their importance, security teams often lack complete ... Read More

How To Talk to Your Board About SAP Security: Three Tips From Former Google CISO
How To Talk to Your Board About SAP Security: Three Tips From Former Google CISO maaya.alagappan Fri, 01/06/2023 - 05:22 Gerhard Eschelbeck recently sat down with Onapsis CEO Mariano Nunez to answer three questions on how to talk to your board about the importance of ERP application security but also ... Read More

A Look Back at SAP Vulnerabilities in 2022
A Look Back at SAP Vulnerabilities in 2022 maaya.alagappan Thu, 01/05/2023 - 14:45 2022 was another eventful year for the Onapsis Research Labs team, as we continue to provide impactful threat intelligence for our customers and educate the broader communities on how to protect their SAP applications and organizations from ... Read More

AppsMas: 2023 ERP Security Predictions
AppsMas: 2023 ERP Security Predictions maaya.alagappan Tue, 12/27/2022 - 14:24 Cyberattacks on business-critical ERP applications are becoming more common and more complex, resulting in new laws being passed to protect organizations and consumers, putting security at the forefront of decision making. As we head into 2023, Onapsis executives share their ... Read More

The Risks of SAP RFC Callbacks and How to Avoid Them
The Risks of SAP RFC Callbacks and How to Avoid Them maaya.alagappan Tue, 12/06/2022 - 17:15 In our recent blog on how to protect your SAP system with the Unified Connectivity Framework (UCON), we talked about minimizing the risk of malicious Remote Function Calls (RFC) into an SAP Production system ... Read More

Protect SAP Systems With Unified Connectivity Framework (UCON)
Protect SAP Systems With Unified Connectivity Framework (UCON) maaya.alagappan Mon, 12/05/2022 - 15:36 Introduction SAP systems intended for development, quality assurance, or training are usually less protected than production systems. Since these systems are usually not completely isolated from the production environment, they are still exposed to risk. One critical ... Read More

AppsMas 2022: ERP Security Resources
AppsMas 2022: ERP Security Resources maaya.alagappan Thu, 12/01/2022 - 16:06 We’re back for a second time with our holiday tradition, AppsMas! Over the next few weeks, we’ll be sharing blogs that cover best practices for protecting your SAP applications, a look back at the 2022 ERP threat landscape, and predictions ... Read More

Onapsis Research Labs Discovers and Helps Remediate 1,000+ Cybersecurity Vulnerabilities in Business Applications
Onapsis Research Labs Discovers and Helps Remediate 1,000+ Cybersecurity Vulnerabilities in Business Applications maaya.alagappan Wed, 11/02/2022 - 06:49 We’re thrilled to announce that Onapsis Research Labs, our team of offensive security professionals dedicated to hunting down vulnerabilities within ERP applications, has discovered and helped remediate over 1,000 zero day ERP ... Read More

Threat Actors Exploit ERP Vulnerabilities for Financial Gain
Threat Actors Exploit ERP Vulnerabilities for Financial Gain maaya.alagappan Wed, 10/26/2022 - 12:49 ERP systems, such as SAP and Oracle E-Business Suite (EBS), are the operational engine of an organization, running the business-critical applications and holding the data needed for businesses to function. These systems are essential to the organization, yet ... Read More

Older, Unpatched ERP Vulnerabilities Continue to Haunt Organizations
Older, Unpatched ERP Vulnerabilities Continue to Haunt Organizations maaya.alagappan Fri, 10/14/2022 - 15:58 It’s the season of ghosts, witches and goblins, but that’s not what's keeping cybersecurity professionals up at night…It’s the challenge of how to identify vulnerabilities, prioritize patches, and prevent cyberattacks targeting business-critical Enterprise Resource Planning (ERP) data ... Read More