< ciso
brief />
Tag Banner

All news with #saas security tag

65 articles

Smashing Security Ep 486: Vibe‑Coded Shops Risk

📰 Smashing Security episode 486 features Graham Cluley and guest Dave Bittner discussing misconfigured AI-built websites, notably a New Zealand store using Base44 that left its site editable by anyone. The episode covers humorous consequences (crusty socks, Princess Diana plates, a Laser Kiwi) and broader concerns about low‑expertise users adopting AI site builders without proper security settings. The hosts also mention past Base44 flaws and consider the risks to small businesses adopting these tools.
read more →

Fake AI subscription sites pose enterprise data risks

🛡️ Malwarebytes found polished websites impersonating reputable AI tools and selling subscriptions, using genuine Google authentication to appear legitimate. These sites request uploads of documents or recordings and charge from $10/month to $2,000/year while concealing real operator details. Researchers suspect a single kit and operator power multiple clones, and warn of shadow IT risk when departments buy without IT involvement.
read more →

BigCommerce warns merchants of Ribon app breach

🔔 BigCommerce alerted merchants after attackers compromised credentials for third-party Ribon applications and injected malicious scripts into a subset of storefronts. The platform confirmed the compromise on September 17, removed the affected apps, and said its core systems were not breached. Affected merchants, including UK retailer Master of Malt, reported exposure of shopper names, emails, phone numbers, and shipping addresses.
read more →

Cloudflare CASB adds automatic remediation policies

🔒 Cloudflare introduces automatic remediation policies for Cloudflare CASB, enabling security teams to define event-driven responses that revoke risky file shares or dispatch custom webhooks without manual steps. CASB previously provided visibility into SaaS misconfigurations; the new feature extends that visibility with native, automated remediation executed via Cloudflare One. Policies run on the Cloudflare developer platform and Workflows to ensure durable, rate-limit aware execution and deliver completion logs for audit and compliance.
read more →

How partners can maximize cloud marketplace value

🛒 Cloud marketplaces are becoming a primary procurement route and offer partners a chance to move beyond transactions to deliver services and long-term value. Palo Alto Networks highlights the importance of meeting customers where they buy, understanding CSP commitments and leveraging the NextWave Partner Program for commercial benefits. Partners can combine platform technology with services to drive adoption, modernize infrastructure and secure emerging priorities like AI. Effective collaboration among partners, CSPs and vendor teams is key to converting marketplace opportunities into strategic customer outcomes.
read more →

Black Hat roundup: Security vendors and AI trends

🔍 Andy Ellis reviews the vendor landscape at Black Hat, highlighting pervasive AI influence across booths and product messaging. He notes that while many vendors emphasize AI in Identity, SaaS, AppSec, and Data, nearly half did not explicitly reference agents or AI in their taglines. Ellis also identifies a market trichotomy: tools that report risk, tools that stop adversaries, and tools that prevent incidents, with diagnostic tools arguably overrepresented.
read more →

Communication Channels and Identity Risks in SaaS Era

🛡️ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more →

Approved-App Blind Spot in AI Security

🔎 An employee shifts between enterprise and personal AI accounts, enabling new features, integrations, and browser extensions that change data paths and actions without downloading overtly malicious software. Approval captures a version of an application at a point in time, but AI features evolve rapidly and can transform an approved app into an ungoverned workflow. Shadow AI occurs when identity, feature, integration, data, purpose, or action change the security state, necessitating continuous interaction-level visibility and controls.
read more →

Amazon Quick introduces approval policies for sharing

🔒 Administrators can now enforce approval policies in Amazon Quick to govern how assets are shared across their organization. Policies can be scoped to asset types such as knowledge bases, spaces, and custom chat agents, routing share requests to designated approver groups. Approvers can inspect assets (including full dependency packages for custom agents) and approve or deny requests, while all actions are logged to AWS CloudTrail for auditability. The capability is available on Professional and Enterprise plans in Regions that support Amazon Quick agentic features.
read more →

Why chat agents can read your unsent messages

💬 Live chat widgets on many websites include a real-time typing preview that lets agents see everything you type, even drafts you never send. This feature is common across popular customer support platforms and is used to speed responses and monitor quality, but it can expose sensitive information without your consent. Users rarely notice the feature and most chat widgets lack an option to disable it. To reduce risk, avoid entering personal data in chat boxes and use security tools to block malicious sites and tracking.
read more →

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

Amazon Connect Customer Outbound Campaigns in Cape Town

📣 Connect Customer Outbound Campaigns (SMS, WhatsApp, email) are now supported in the Africa (Cape Town) Region. Businesses can create targeted, personalized outreach for service updates, promotions, reminders, and product tips using the Connect Customer admin console and Outbound Campaigns APIs. Built-in analytics measure engagement and event-based triggers automate campaign start based on customer actions.
read more →

SaaS single points of failure threaten campuses

📘 Higher education now runs core academic operations on a few massive SaaS platforms, creating systemic single points of failure. When a major LMS was breached during finals week 2026, campuses lost access to rosters, grade books and coursework despite SLAs and certifications. The author argues IT must architect independent, read-only continuity layers synchronized from source systems to maintain operations during vendor outages or attacks.
read more →

Shadow AI: Timing, Not Just Tools

🛡️ Most AI policies are written for the future while employees use AI now, creating a temporal gap that produces shadow AI. Security often learns of risky interactions only after prompts, uploads, or actions have occurred, making after-the-fact visibility insufficient. Effective governance must reach the moment of use, combining permission with contextual judgment and offering fast, practical controls that match employee workflows.
read more →

Check Point expands Claude compliance coverage

🔒 Check Point now integrates its Workforce AI governance with Claude’s Compliance API to close substantial visibility gaps in enterprise AI usage. The integration provides continuous, audit-grade records across web, desktop, and mobile surfaces, addressing a critical mobile blind spot that proxies, CASBs, and endpoint DLP cannot cover. It combines content-level exposure analysis, per-user adoption analytics, and unified policy enforcement to enable secure, frictionless AI adoption across the organization.
read more →

Lessons from the Canvas LMS cyberattack

🔒 Over May 6–7, 2026, Canvas LMS users encountered a defaced login page claiming a ShinyHunters extortion of Instructure, alleging theft of 3.65TB of data affecting about 275 million students, faculty, and staff across nearly 9,000 institutions. Instructure identified an exploited support-ticket vulnerability in its Free for Teacher environment and temporarily disabled that service while investigating. The incident disrupted finals and highlighted risks from centralized SaaS platforms, third-party dependencies, communications breakdowns and the evolving economics of extortion.
read more →

Shadow AI and the Rise of Vibe‑Coded Application Risk

🔎 Shadow AI now describes employees building full applications with AI and publishing them without IT or security involvement. Red Access' Shadow Builders report found over 380,000 public assets on vibe‑coding platforms, with more than 2,000 exposing sensitive corporate or personal data. Existing security controls miss these builds because the entire lifecycle — OAuth grants, data movement, and publishing — occurs inside web sessions that traditional tools only partially observe.
read more →

LayerX Report Reveals Concentrated Enterprise AI Risk

🔍 The LayerX Security State of AI Usage Report 2026 finds enterprise AI risk is concentrated among a small set of power users and a few dominant platforms, while usage fragments across personal accounts, browser extensions, embedded copilots, and connectors. The study shows ChatGPT still dominates conversations, Copilot M365 is growing, and consumer AI like Gemini is often used via personal accounts. Shadow AI now spans a long tail of under-the-radar tools and extensions that evade corporate visibility and governance.
read more →

Cloudflare CASB Adds Claude Compliance API Support

🔒 Cloudflare has extended its Cloud Access Security Broker (CASB) to support the Claude Compliance API, enabling security and compliance teams to monitor Claude Enterprise activity directly in the Cloudflare dashboard without endpoint agents. The integration surfaces security findings for projects, attachments, chat files, messages, and provider-generated artifacts, and groups findings by category and severity. Customers can immediately convert findings into enforcement actions via Gateway policies and use existing detection and remediation workflows. Setup requires a Claude Enterprise account and Compliance API access, and the integration begins scanning and surfacing findings within minutes.
read more →

Detecting and Blocking Unsanctioned AI in the Enterprise

🔍 While many organizations intentionally deploy AI to improve productivity, unsanctioned AI is proliferating faster — employees install tools or vendors embed assistants into existing apps. The article defines four AI categories and maps specific detection techniques to each, covering DNS, web gateways/NGFW, EPP/EDR, application and browser controls, and SSPM/identity governance. It flags OAuth consent as a high-risk channel and summarizes admin steps for Microsoft Entra, Google Admin, Salesforce, and ServiceNow to block or restrict app access.
read more →