Onapsis Podcast

Onapsis Podcast

Protecting Brand Value: An Executive Threat Briefing on SAP Security

Download it: MP3 | AAC | OGG | OPUS

For the world’s leading luxury houses, SAP is not just enterprise software. It is the silent guardian of client discretion, heritage sourcing, and the operational precision that defines your maison.

As luxury brands accelerate cloud and AI-driven transformation, sophisticated threat actors are evolving in parallel. They are no longer stopping at perimeter defenses. They are moving directly into the enterprise core, where a single breach can compromise client trust, disrupt limited-edition allocations, and erode the brand mystique you have spent decades cultivating.

Because in luxury, a breach is not just operational. It is reputational.

You Will Learn:
Anatomy of an SAP Breach: How attackers pivot from adjacent systems into the SAP core, and why traditional defenses are insufficient
Luxury-Specific Business Impact: Quantifying brand equity loss, client trust erosion, and the operational fallout of SAP compromise
The Compliance Myth: Why being audit-ready does not equal being secure
A Roadmap to Resilience: Practical steps to harden SAP environments while preserving the client experience

Hacking & Defending SAP Live: How Mythos-like AI Models Can Hack SAP Applications

Download it: MP3 | AAC | OGG | OPUS

Historically, compromising SAP environments required years of specialized, niche knowledge of proprietary architecture. AI LLMs like Mythos, GPT-5.5-Cyber and even open source ones have obliterated that barrier to entry. Today, AI-powered offensive tools are democratizing cybercrime, translating complex SAP architectures for average attackers and enabling them to find, weaponize, and execute exploits against SAP applications at scale.

In this episode we demonstrate real-world scenarios on how threat actors are able to leverage AI to map out vulnerabilities in SAP applications, generate precise exploits and execute sophisticated attacks to breach the SAP core. By leveraging AI as a force multiplier, virtually anyone can now orchestrate sophisticated attacks that bypass generic security controls and compromise critical business data.

Once you understand how sophisticated threats are being used to compromise SAP applications, we will show you how to protect yourself and secure your systems to ensure operational resilience.

Key Takeaways

- How attackers use LLMs to decipher complex SAP architectures, leverage proprietary protocols, and craft targeted exploits without prior SAP training.
- A live demonstration of AI-driven compromise within the SAP application layer.
- Witnessing an attacker use AI to move laterally to the SAP core and access sensitive business data.
- How Onapsis equips security teams with the automated visibility, governance and defense needed to counter AI-paced offensive threats.

Fireside Chat: Security and Compliance in the Shared Responsibility Model with OG&E and Onapsis

Download it: MP3 | AAC | OGG | OPUS

In partnership with Onapsis, this ASUG webcast will deliver insights designed to support your work with SAP technology.

RISE with SAP delivers significant technological and procedural advancements to help organizations address evolving business needs. Central to the solution is the Shared Responsibility Model, which outlines the roles of customers, partners, and SAP in jointly delivering business value. But don’t let the word “shared” mislead you—responsibility doesn’t always mean accountability.

The decisions you make at the very start of your project can define the success of your build, go-live, and hypercare phases. Join Ian Anderson from Oklahoma Gas & Electric Company as he shares real-world insights on navigating this new model. Learn how early strategic choices—both procedural and technical—laid the groundwork for sustained success throughout their RISE with SAP journey.

Hacking & Defending SAP Applications Live: Clean Core, Dark Shadows

Download it: MP3 | AAC | OGG | OPUS

As organizations adopt a Clean Core strategy, the attack surface of the SAP landscape has split into two distinct fronts: the rapid innovation of SAP BTP developments and the deep-rooted complexity of ABAP custom code. Security can no longer afford to treat these as blindspots. One missed vulnerability in a BTP app can leak your most sensitive data; one rogue line of ABAP can grant a rogue developer the keys to the kingdom.

In this episode, we present two high-stakes threat scenarios, based on real-world incidents, that every SAP customer must prepare for:

The BTP Blindspot: We demonstrate how an innocent developer mistake in a custom BTP application, such as an insecure API endpoint or a broken authentication check, becomes an open door to the core of the business. Watch as an attacker exploits this flaw without any credentials to silently exfiltrate sensitive enterprise data.
The Trojan Horse: We go deep into the ABAP core to show how a rogue developer or contractor can bypass standard checks to insert a sophisticated backdoor in an ABAP program. By injecting a few lines of malicious code, the actor secures SAP_ALL privileges, allowing them to modify financial records and master data in production while bypassing compliance controls.

The Unprecedented Rise in SAP Attacks: Lessons from Mandiant & Onapsis

Download it: MP3 | AAC | OGG | OPUS

For years, the sheer complexity of SAP environments provided a form of security through obscurity. The newly released Mandiant 2026 M-Trends Report shatters this paradigm. According to the data, SAP NetWeaver has emerged as the most exploited enterprise vulnerability of the year. Threat actors are no longer stumbling into these environments; they are targeting them with unprecedented speed and precision.

This session moves beyond basic patching to dissect the latest zero-day exploit campaigns, evaluate the impact of AI-driven threats, and outline a unified defense strategy to protect your most critical business-operational assets.

Executive Takeaways

The M-Trends Revelations: A direct briefing on the key findings from Mandiant’s M-Trends 2026 Report and why SAP NetWeaver is now the prime target.
Impact of a Zero-Day: An overview of the active exploit campaign and how threat actors operate inside the application layer.
AI Acceleration: Understanding how AI is shrinking defender response windows and how to counter automated threats.
Continuous Resiliency: Joint actionable guidance from Mandiant and Onapsis to proactively secure your systems and eliminate critical security silos.

Hacking & Defending SAP Applications Live: The SAP Zero-Day That Changed Everything

Download it: MP3 | AAC | OGG | OPUS

This webinar offers a comprehensive analysis of CVE-2025-31324, the first mass-exploited SAP zero day vulnerability. Onapsis Research Labs successfully intercepted and reverse-engineered the complete, multi-stage exploit chain used by sophisticated threat actors. The attack methodology will be detailed—from the initial vulnerability trigger to post-exploitation persistence. The presentation includes a live demonstration of the attack, outlines the immediate, tactical countermeasures developed in joint collaboration with SAP to ensure effective security implementation, and how Onapsis customers stay ahead of the threat.

From Discovery to Defense: SAP & Onapsis Joint Response to Zero-Day CVE-2025-31324

Download it: MP3 | AAC | OGG | OPUS

When zero-day CVE-2025-31324 surfaced, organizations had to react quickly. SAP and Onapsis worked closely to analyze the threat, validate exploitation activity, and deliver protections for customers worldwide.

In this joint session, you’ll get a behind-the-scenes look at how security research and collaboration accelerate guidance, patching, and response to this zero-day. Hear from the experts about what happened, what was learned, and what every SAP customer should be doing now to strengthen their landscape.

Key Takeaways:

Recommended steps SAP customers should take to reduce future risk

SAP’s quick response to address CVE-2025-31324
How SAP and Onapsis collaborated to better understand what threat actors were exploiting
Timeline walkthrough: from discovery to analysis to guidance
What active exploitation revealed about modern SAP threat actors
How SAP & Onapsis Research Labs collaboration strengthens enterprise resilience

The State of SAP Security: 2025 Vulnerabilities, Exploits & Lessons Learned

Download it: MP3 | AAC | OGG | OPUS

Your SAP applications aren’t just software—they’re the lifeblood of your business. In today’s threat landscape, relying on generic security isn’t enough. You need tailor-made, enterprise-grade protection.
2025 was a pivotal year for SAP security, marked by critical vulnerabilities, zero-day exploits, and evolving attacker tactics targeting business-critical systems.

JP Perez-Etchegoyen and Paul Laudanski from Onapsis Research Labs (ORL) recap the top SAP security vulnerability trends from 2025, provide an anatomy of real attacks to SAP Applications, and share practical guidance to help you strengthen your SAP defenses for 2026.

You’ll learn:

Key lessons from 2025’s most impactful SAP vulnerabilities and exploits
How threat actors are exploiting vulnerabilities like CVE-2025-31324
Actionable steps to take now to protect your SAP landscape from known exploits and future vulnerabilities
Detailing steps to secure your SAP landscape in 2026 with a webinar-exclusive checklist

Defending What Matters Most: Smarter, Faster Incident Response with Onapsis and Microsoft Sentinel for SAP

Download it: MP3 | AAC | OGG | OPUS

2025 has proven to be a real “wake up call” for SAP security, marked by critical zero-days, public exploits, a significant rise in sophisticated threat actor activity, and hundreds of global enterprises compromised after waves of targeted attacks that continue to this day. Security teams are struggling to keep pace – especially when it comes to unfamiliar, complex software such as SAP. These teams frequently lack the deep SAP threat insights and specialized exploit detection that today’s modern SAP attack landscape requires in order to effectively defend these mission-critical business systems.

This webinar will provide security professionals with an in-depth, educational look at both the latest tactics, techniques, and procedures used by threat actors to directly attack SAP, as well as the next-gen methodologies and tooling required to defend against them.

You will learn:

How Onapsis Defend and Microsoft Sentinel for SAP integrate together to help customers defend their critical systems against increasingly successful SAP cyberattacks
Key lessons from 2025’s most impactful SAP vulnerabilities, exploits, and breaches
The latest exploit detection, response automation, and AI capabilities your team should be leveraging to accelerate and optimize your SAP incident response

The Technology Leader’s 2025 Agenda for SAP

Download it: MP3 | AAC | OGG | OPUS

This on-demand webinar delves into the key findings from the SAPinsider Benchmark Research report, “The Technology Leader’s 2025 Agenda for SAP.” This session will break down the strategies and investments that technology leaders are prioritizing as they navigate the shift to SAP S/4HANA and the growing influence of AI.

In this session, we’ll cover:

Business Priorities: Discover the top business priorities for technology leaders in 2025, with a deep dive into why increasing process efficiency and building an AI strategy are at the top of the list.
Investment Trends: Understand where technology leaders are directing their budgets, including strategic investments in current and new AI technologies, SAP S/4HANA, and data warehousing platforms.
The Talent Gap: Learn about the most in-demand SAP-related skills and how companies are preparing their teams for the challenges of SAP S/4HANA migration and AI deployment.
Overcoming Challenges: Hear about the biggest roadblocks to AI deployment, such as a lack of clean data and security concerns, and learn how to address them responsibly.

About this podcast

Welcome to our Onapsis Podcast, a podcast brought to you by Onapsis, the global leader in SAP cybersecurity.

Join us as we delve into the fascinating world of safeguarding SAP systems from cyber threats and uncover the secrets to protecting your organization's most critical assets.
In each episode, our expert hosts and special guests will explore a variety of captivating topics surrounding SAP cybersecurity, shedding light on the challenges, best practices, and cutting-edge solutions that help businesses maintain the integrity and resilience of their SAP landscapes.
From the latest emerging threats to innovative techniques for vulnerability management and threat detection, our podcast provides invaluable insights for professionals working with SAP systems or those interested in learning more about the importance of securing the digital core.

by Onapsis

Subscribe

Follow us