How to Enact a SaaS Compliance Strategy for NIS2 and DORA

How to Enact a SaaS Compliance Strategy for NIS2 and DORA

Critical data has migrated to SaaS, and attackers are taking advantage of this new avenue for exploitation—monthly SaaS breaches are up 300% year over year. Due to the critical role SaaS applications ...
Rethinking Identity Threat Detection: Don’t Rely on IP Geolocation

Rethinking Identity Threat Detection: Don’t Rely on IP Geolocation

SOC teams frequently look to the IP geolocation to determine whether an alert or activity poses a genuine threat.  However, with the changing threat landscape, relying solely on this information is no ...
SaaS Under Siege: Nation-State Actors Target Identities

SaaS Under Siege: Nation-State Actors Target Identities

TL;DR – Like bank robbers and banks, nation-state actors are now targeting SaaS because that’s where the currency is. Plus, now it’s even easier than traditional endpoint compromise. In case you missed ...
Timeline of Microsoft Breach by Russian Hackers

Behind The Breach: Microsoft Breach by Russian Hackers

On 12 January 2024, Microsoft disclosed a critical breach carried out by Russian state-sponsored group, Midnight Blizzard. The threat actor used a password-spraying attack to gain unauthorized access to Microsoft Corporation’s Office ...
â„¢

Securing Against OAuth Exploitation: A Step-By-Step Guide

Recent findings from Microsoft Threat Intelligence reveal a concerning trend: threat actors exploiting vulnerabilities in Microsoft 365 and Azure environments to execute attacks, with a focus on OAuth application abuse. In this ...
â„¢

Obsidian Security Recognized as Strong Performer by Independent Research Firm

Today, our team at Obsidian Security has been recognized as a Strong Performer by The Forrester Waveâ„¢: SaaS Security Posture Management, Q4 2023. We believe such acknowledgment is reflective of the work ...

Salesforce Misconfigurations are Exposing Sensitive Data

Just last week, cybersecurity journalist Brian Krebs shared a post to his website detailing how Salesforce misconfigurations were causing several organizations to inadvertently expose sensitive data to the public. Affected organizations, which ...

Salesforce Misconfigurations are Exposing Sensitive Data

Just last week, cybersecurity journalist Brian Krebs shared a post to his website detailing how Salesforce misconfigurations were causing several organizations to inadvertently expose sensitive data to the public. Affected organizations discovered ...
Learn with Obsidian Lightboards: SaaS Compliance, SaaS Incident Response, and more!

Learn with Obsidian Lightboards: SaaS Compliance, SaaS Incident Response, and more!

It’s Obsidian’s inaugural SSPM Week, and over these last few days we’ve announced a number of exciting releases and additions to our platform. Managing SaaS integration risk, measuring and maintaining SaaS compliance, ...