Le Lézard
Classified in: Science and technology
Subjects: Contract/Agreement, Product/Service

New Report Reveals Evidence of Increased Cybercriminal Interest in ERP Applications


New research from threat data and intelligence leader Flashpoint and ERP cybersecurity and compliance leader Onapsis reveals evidence that SAP business-critical applications are increasingly top of mind and valuable for cybercriminals. The report shows a significant rise in threat actor groups targeting SAP vulnerabilities, and aids defenders with actionable intelligence to ensure their mission-critical SAP applications are protected from these threats.

2023 was a critical inflection point for the SAP application threat landscape with new highs in threat activity and increased interest from prolific and well-established threat actor groups and state-sponsored cyberespionage groups. All SAP vulnerabilities observed within this report were patched by SAP several years ago, with SAP having made the relevant SAP Security Notes promptly available for customers. This indicates that threat actors continue to target and exploit organizations with weak cybersecurity governance for SAP applications, mostly taking advantage of known, unpatched SAP vulnerabilities and misconfigurations. This is of special relevance as customers migrate SAP applications to the cloud, further increasing their exposure to a growing number of threat actors.

This report from Onapsis Research Labs in collaboration with Flashpoint highlights the evolution of this threat landscape for SAP applications over the past four years and how the growing maturity of this cybercriminal market presents stark challenges to defenders of organizations globally. This collaborative research report reveals:

Rising Threats Against SAP Applications

Increased Evidence of Ransomware Attacks on SAP

Increased Discussion and Interest in SAP Exploitation

Significant Growth in Threat Community Engagement

Proactive Measures and Warnings

The vast majority of large organizations utilize ERP applications from leading vendors like SAP and Oracle, incorporating solutions such as SAP Business Suite, SAP S/4HANA, and Oracle E-Business Suite/Financials. These applications are crucial for supporting a wide array of business processes, including payroll, treasury, inventory management, manufacturing, financial planning, sales, logistics, and more. They are also pivotal in managing and hosting a vast range of sensitive data. This encompasses financial results, manufacturing formulas, pricing strategies, critical intellectual property, and sensitive information like credit card details and personally identifiable information (PII) of employees, customers, and suppliers.

Some companies are falling behind when it comes to ERP cybersecurity due to the lack of information about the threat actors in what was considered by many information security teams to be a complex and obscure domain.

The growing focus on ERP applications by cybercriminals highlighted in this report reflects a critical evolution in the threat landscape. It's essential for organizations to integrate comprehensive threat intelligence into their security protocols to effectively counter these advanced threats," said Christian Rencken, Senior Strategic Advisor at Flashpoint.

"This collaboration with Flashpoint provides a depth of threat intelligence that is critical for both security and SAP teams to understand," said Juan Pablo (JP) Perez-Etchegoyen, CTO at Onapsis. "By showing how these applications are being targeted and the increasing frequency, we hope to help CIOs, CISOs and their teams manage the risk of wide-scale attacks."

Download the report and hear from JP Perez-Etchegoyen and Christian Rencken, Senior Strategic Advisor at Flashpoint, as they detail this research live on April 24.

ABOUT FLASHPOINT

Flashpoint is the pioneering leader in threat data and intelligence. We empower commercial enterprises and government agencies to decisively confront complex security challenges, reduce risk, and improve operational resilience amid fast-evolving threats. Through the Flashpoint Ignite platform, we deliver unparalleled depth, breadth and speed of data from highly relevant sources, enriched by human insights. Our solutions span cyber threat intelligence, vulnerability intelligence, geopolitical risk, physical security, fraud and brand protection. The result: our customers safeguard critical assets, avoid financial loss, and protect lives. Discover more at flashpoint.io.

ABOUT ONAPSIS

Onapsis protects the business applications that run the global economy. The Onapsis Platform delivers vulnerability management, change assurance, and continuous compliance for business applications from leading vendors such as SAP, Oracle, and others. The Onapsis Platform is powered by the Onapsis Research Labs, the team responsible for the discovery and mitigation of more than 1,000 zero-day vulnerabilities in business applications.

Connect with Onapsis on LinkedIn, X, or visit https://www.onapsis.com.


These press releases may also interest you

at 16:10
Senseonics Holdings, Inc. , a medical technology company focused on the development and manufacturing of long-term, implantable continuous glucose monitoring (CGM) systems for people with diabetes, today announced that it plans to release its first...

at 16:10
Gilead Sciences, Inc. announced today that its executives will be speaking at the following investor conferences: BofA Securities Health Care Conference on Tuesday, May 14 at 11:20am Pacific Time RBCCM Global Healthcare Conference on...

at 16:10
Spruce Biosciences, Inc. , a late-stage biopharmaceutical company focused on developing and commercializing novel therapies for rare endocrine disorders with significant unmet medical need, today announced that an accepted abstract highlighting...

at 16:10
A10 Networks, Inc. , a leading provider of cybersecurity and infrastructure solutions, today announced financial results for its first quarter ended March 31, 2024. First Quarter 2024 Financial Summary Revenue of $60.7 million, in-line with...

at 16:10
Vir Biotechnology, Inc. today announced that Marianne De Backer, M.Sc., Ph.D., MBA, Chief Executive Officer is scheduled to participate in a fireside chat at the BofA Securities Healthcare Conference 2024 on Tuesday, May 14, at 4:20 p.m. PT / 7:20...

at 16:10
Super Micro Computer, Inc. , a Total IT Solution Provider for AI, Cloud, Storage and 5G/Edge, today announced financial results for its third quarter of fiscal year 2024 ended March 31, 2024. Third Quarter Fiscal Year 2024 Highlights Net sales...



News published on and distributed by: