< ciso
brief />
Tag Banner

All news with #saas security tag

59 articles

Communication Channels and Identity Risks in SaaS Era

πŸ›‘οΈ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more β†’

Approved-App Blind Spot in AI Security

πŸ”Ž An employee shifts between enterprise and personal AI accounts, enabling new features, integrations, and browser extensions that change data paths and actions without downloading overtly malicious software. Approval captures a version of an application at a point in time, but AI features evolve rapidly and can transform an approved app into an ungoverned workflow. Shadow AI occurs when identity, feature, integration, data, purpose, or action change the security state, necessitating continuous interaction-level visibility and controls.
read more β†’

Amazon Quick introduces approval policies for sharing

πŸ”’ Administrators can now enforce approval policies in Amazon Quick to govern how assets are shared across their organization. Policies can be scoped to asset types such as knowledge bases, spaces, and custom chat agents, routing share requests to designated approver groups. Approvers can inspect assets (including full dependency packages for custom agents) and approve or deny requests, while all actions are logged to AWS CloudTrail for auditability. The capability is available on Professional and Enterprise plans in Regions that support Amazon Quick agentic features.
read more β†’

Why chat agents can read your unsent messages

πŸ’¬ Live chat widgets on many websites include a real-time typing preview that lets agents see everything you type, even drafts you never send. This feature is common across popular customer support platforms and is used to speed responses and monitor quality, but it can expose sensitive information without your consent. Users rarely notice the feature and most chat widgets lack an option to disable it. To reduce risk, avoid entering personal data in chat boxes and use security tools to block malicious sites and tracking.
read more β†’

The SaaS blind spot: visibility gaps in cloud apps

πŸ” Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps β€” audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews β€” can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more β†’

Amazon Connect Customer Outbound Campaigns in Cape Town

πŸ“£ Connect Customer Outbound Campaigns (SMS, WhatsApp, email) are now supported in the Africa (Cape Town) Region. Businesses can create targeted, personalized outreach for service updates, promotions, reminders, and product tips using the Connect Customer admin console and Outbound Campaigns APIs. Built-in analytics measure engagement and event-based triggers automate campaign start based on customer actions.
read more β†’

SaaS single points of failure threaten campuses

πŸ“˜ Higher education now runs core academic operations on a few massive SaaS platforms, creating systemic single points of failure. When a major LMS was breached during finals week 2026, campuses lost access to rosters, grade books and coursework despite SLAs and certifications. The author argues IT must architect independent, read-only continuity layers synchronized from source systems to maintain operations during vendor outages or attacks.
read more β†’

Shadow AI: Timing, Not Just Tools

πŸ›‘οΈ Most AI policies are written for the future while employees use AI now, creating a temporal gap that produces shadow AI. Security often learns of risky interactions only after prompts, uploads, or actions have occurred, making after-the-fact visibility insufficient. Effective governance must reach the moment of use, combining permission with contextual judgment and offering fast, practical controls that match employee workflows.
read more β†’

Check Point expands Claude compliance coverage

πŸ”’ Check Point now integrates its Workforce AI governance with Claude’s Compliance API to close substantial visibility gaps in enterprise AI usage. The integration provides continuous, audit-grade records across web, desktop, and mobile surfaces, addressing a critical mobile blind spot that proxies, CASBs, and endpoint DLP cannot cover. It combines content-level exposure analysis, per-user adoption analytics, and unified policy enforcement to enable secure, frictionless AI adoption across the organization.
read more β†’

Lessons from the Canvas LMS cyberattack

πŸ”’ Over May 6–7, 2026, Canvas LMS users encountered a defaced login page claiming a ShinyHunters extortion of Instructure, alleging theft of 3.65TB of data affecting about 275 million students, faculty, and staff across nearly 9,000 institutions. Instructure identified an exploited support-ticket vulnerability in its Free for Teacher environment and temporarily disabled that service while investigating. The incident disrupted finals and highlighted risks from centralized SaaS platforms, third-party dependencies, communications breakdowns and the evolving economics of extortion.
read more β†’

Shadow AI and the Rise of Vibe‑Coded Application Risk

πŸ”Ž Shadow AI now describes employees building full applications with AI and publishing them without IT or security involvement. Red Access' Shadow Builders report found over 380,000 public assets on vibe‑coding platforms, with more than 2,000 exposing sensitive corporate or personal data. Existing security controls miss these builds because the entire lifecycle β€” OAuth grants, data movement, and publishing β€” occurs inside web sessions that traditional tools only partially observe.
read more β†’

LayerX Report Reveals Concentrated Enterprise AI Risk

πŸ” The LayerX Security State of AI Usage Report 2026 finds enterprise AI risk is concentrated among a small set of power users and a few dominant platforms, while usage fragments across personal accounts, browser extensions, embedded copilots, and connectors. The study shows ChatGPT still dominates conversations, Copilot M365 is growing, and consumer AI like Gemini is often used via personal accounts. Shadow AI now spans a long tail of under-the-radar tools and extensions that evade corporate visibility and governance.
read more β†’

Cloudflare CASB Adds Claude Compliance API Support

πŸ”’ Cloudflare has extended its Cloud Access Security Broker (CASB) to support the Claude Compliance API, enabling security and compliance teams to monitor Claude Enterprise activity directly in the Cloudflare dashboard without endpoint agents. The integration surfaces security findings for projects, attachments, chat files, messages, and provider-generated artifacts, and groups findings by category and severity. Customers can immediately convert findings into enforcement actions via Gateway policies and use existing detection and remediation workflows. Setup requires a Claude Enterprise account and Compliance API access, and the integration begins scanning and surfacing findings within minutes.
read more β†’

Detecting and Blocking Unsanctioned AI in the Enterprise

πŸ” While many organizations intentionally deploy AI to improve productivity, unsanctioned AI is proliferating faster β€” employees install tools or vendors embed assistants into existing apps. The article defines four AI categories and maps specific detection techniques to each, covering DNS, web gateways/NGFW, EPP/EDR, application and browser controls, and SSPM/identity governance. It flags OAuth consent as a high-risk channel and summarizes admin steps for Microsoft Entra, Google Admin, Salesforce, and ServiceNow to block or restrict app access.
read more β†’

Five Practical Steps to Manage Shadow AI Tools Securely

πŸ” Across organizations, employees run three to five AI tools dailyβ€”many unapproved and often connected to corporate data via OAuth, browser extensions, or newly added vendor featuresβ€”creating a widening "shadow AI" gap that evades traditional network controls. The article outlines five practical steps security teams can apply: build an inventory, write usable policies, create a fast approval lane, implement browser-native monitoring, and deliver just-in-time coaching. Together these measures aim to preserve productivity while restoring visibility, reducing data exposure, and aligning employee workflows with security requirements.
read more β†’

Webinar: Why MSPs Must Rethink Security and Recovery

πŸ”’ On May 14, 2026 at 2:00 PM ET, BleepingComputer will host a live webinar titled From phishing to fallout: Why MSPs must rethink both security and recovery with Austin O'Saben and Adam Marget of Kaseya. The session examines how AI-driven phishing, business email compromise, ransomware, and SaaS compromise are reshaping the threat landscape for managed service providers. Attendees will learn why prevention and recovery must operate together and how SaaS backups and a formal BCDR plan can reduce downtime and data loss.
read more β†’

Orphaned Applications Fuel Shadow IT and Risk Exposure

πŸ”Ž Orphaned applications silently expand shadow IT by persisting beyond team ownership, continuing to authenticate, exchange data, and consume resources without oversight. They commonly appear when departments adopt tools to meet urgent needs and those workflows, accounts, or service identities are never decommissioned. NETSCOUT Smart Data leverages packet-derived observability to reveal hidden dependencies and enrich the ServiceNow CMDB, helping teams reduce operational, security, and compliance blind spots.
read more β†’

Amazon Quick Adds 13 Connectors for Google Workspace and More

πŸ”— Amazon Quick now provides 13 new built-in action connectors that let business users take direct actions across Google Workspace, Zoom, Airtable, QuickBooks, Dropbox, and Microsoft Teams without leaving the assistant. Each connector supports managed authentication, enabling secure account connections in a few clicks without manual credential handling. The connectors handle authorization flows on behalf of users and are available in all AWS Regions where Amazon Quick is offered.
read more β†’

CrowdStrike Expands ChatGPT Enterprise Monitoring Now

πŸ”’ CrowdStrike has expanded its integration with ChatGPT Enterprise to deliver deeper audit logging and continuous activity monitoring within Falcon Shield SaaS security. The enhancement ingests OpenAI’s expanded logs to capture authentication events, administrative changes, tool and Codex usage, and conversation-level records across workspaces. By correlating AI activity with identity, device, and SaaS telemetry, the capability aims to detect suspicious behaviors, enforce policy, and support faster investigations. This marks a shift from configuration visibility to operational threat detection for AI-driven workflows.
read more β†’

Amazon Quick Adds Co-Owners for SharePoint and Google Drive

πŸ”’ Amazon Quick now supports adding co-owners to admin-managed Microsoft SharePoint Online and Google Drive knowledge bases and their data source connections. Owners receive full management capabilities β€” editing, syncing, sharing, and deleting β€” while Viewers have query-only access. The Owner co-owner option is restricted to admin-managed SharePoint and Google Drive; other knowledge base types support Viewer sharing only. Administrators can also share connections so teams can create knowledge bases from the same integration. The feature is available in all AWS Regions where Amazon Quick is offered.
read more β†’