00:00:00: Hello everyone, thanks for joining today's webinar on protecting brand value through SAP security.
00:00:07: My name is Angelica Cubel and I'll be managing the day session.
00:00:11: Before we get started i have some housekeeping notes.
00:00:14: First ,I want to point out a questions module within the ON-TWENTYFOUR platform.
00:00:19: We welcome you enter your question at any points during this presentation And if time allows .We will answer whatever questions we can.
00:00:29: You can always adjust the size of a media player to make it bigger or smaller depending on your preference.
00:00:36: And finally, please note that this session is being recorded and we'll share our links in this session after we wrap up today!
00:00:44: Now I'm going to pass it over to our presenter.
00:00:47: with us Today We have Paula Laodansi who will be sharing critical insights on SAP security for luxury organizations.
00:00:55: It will be diving deep into the evolving threat landscape.
00:01:00: The business impact of SAP breaches on brand reputation and client trust, and practical steps you can take to strengthen your security posture while protecting the operational precision that defines our
00:01:12: organization.".
00:01:13: And with that I'll hand it over to Paul.
00:01:17: Thank You very much!
00:01:25: And I'm very excited to be able to talk about passions that I have around relationships, passions that i have around demonstrating and translating those relationships in a secure way especially when it comes to doing things with customers.
00:01:44: In an online world.
00:01:46: so It's my joy To Be Able To Talk To You About Protecting Brand Value.
00:01:52: An Executive Threat Briefing on SAP Security.
00:01:58: a little bit about myself.
00:01:59: So as I said, I love relationships and think that is so important to anything we do out there in the world whether through personal connections or business connections or managing brand.
00:02:15: Part of what my team does here at the onapsis research labs We take look at threats targeting SAP.
00:02:26: we try to understand those threats and make sure that we address those threats working with SAP, so when the attackers tried to find them themselves.
00:02:38: The reality is that we were able to get them patched working with SAP a fantastic partner in this journey.
00:02:46: There's a lot of other things I am familiar with have experience as you could see here.
00:02:52: all these are really tied too fundamentally relationships because relationships matter.
00:02:58: If in order to build trust, you have to show up each and every day personal and a business as someone or a business that is trustworthy?
00:03:09: And that's the journey I'm going take on here during this presentation.
00:03:14: It's about demonstrating how attackers understand The importance of relationship.
00:03:20: They understand what it means out there in the business marketplace and how to leverage that relationship.
00:03:29: To try an get what they want, which ultimately is data or finance money will go ahead and dive into that.
00:03:41: first a little bit about the onapsis research labs.
00:03:45: more than I've mentioned.
00:03:47: we've been around for quite awhile.
00:03:49: We are vulnerability research into SAP.
00:03:57: We do a lot more things than research in to SAP and ERP, we do professional services with black box gray box and white box penetration testing.
00:04:08: so we are that third party so-to speak.
00:04:11: they could come in pressure test systems make sure of the day or safe secure before attackers have chance to step in potentially breach which is a lot of what we've seen in twenty-twenty five.
00:04:29: We partner with SAP Product Security Response Team, we partner with CESA and BSI over the research that we do on our global threat intel network.
00:04:44: Throughout the lifetime We've got lots of knowledge base articles, a lot of information that ultimately leads to us sharing that with our customers in the Onapsus platform as well as again working with partners like SAP.
00:05:09: Probably the biggest relationship factor that I want point out is a few years ago when we would present at some of these conferences listed here Black Hat Def Con troopers, especially Black Hat and DefCon.
00:05:27: People in the audience didn't really understand what SAP was but that's changed.
00:05:32: so even in the Audience everyone seems to be aware of What SAP is?
00:05:38: What SAP manages and understands.
00:05:40: That data that SAP works with Is a business critical asset To any company.
00:05:52: Okay this slide SAP is the digital nervous system of your Maison.
00:06:00: I've had to think about this a little bit, and-and this slide really stood out to me in terms of relationships right?
00:06:09: So when we take a look at the supply chain... When We Take A Look At The Client Registry.. When We TAKE A LOOK AT THE RETAIL OPERATIONS AND THE MARKET INTEGRITY That's All About Protecting The Product.
00:06:23: When we see SAP as the digital nervous system of your Maison, it's protecting the product.
00:06:30: Protecting your clientele.
00:06:33: It's protecting The experience Of Your clientele right whether they go into those boutique networks or do They Go Into the e-commerce platforms?
00:06:45: We really want to ensure that As an organization were able To protect That shopping experience.
00:06:54: It's important that brand relationship is so important for consumers and That's the last part, right?
00:07:01: The market integrity.
00:07:03: it's all about protecting to brand.
00:07:05: So it's important for us To make sure that you get the best out of SAP security And SAP threat intelligence in order to apply it and maintain and curate and nourish The protection of the product, the protection of clientele especially high value net worth customers.
00:07:29: Protecting experience that people have with your brands and protecting again brand itself.
00:07:40: one primary note here uh bottom part right it's threat actors understand this.
00:07:51: they're targeting.
00:07:54: not only do people at these conferences now know what SAP is, the threat actors do as well.
00:08:02: We actually have research into The Threat Actor Dark Marketplace—the deep and dark forums It's called the Chatter Report.
00:08:12: That something that you can access off of Anapsis.com?
00:08:16: That's Something You Can Look At from a non-demand webinar.
00:08:19: we dive in to that world And explore how these threat Actors are becoming aware of SAP and how they're getting infiltrated into companies to be able to deploy ransomware in environments that have SAP.
00:08:40: Here's our agenda, so we are going talk about why SAP security is brand security kind of talked a little bit here.
00:08:49: the twenty-twenty five vulnerability landscape were gonna look at how twenty.
00:08:56: twenty five has been an epic year for SAP.
00:09:01: The new threat actors targeting luxury, the anatomy of real SAP breaches and luxury specific business impact.
00:09:10: And finally we'll have a roadmap to resilience with assess control and defend.
00:09:16: those are components of the onapsis platform.
00:09:19: in We the onpsis research labs were that tip-of-the spear.
00:09:24: So the work that we do gets fed directly into that where OOP, Onapsis Platform has information based off of our global threat intel network.
00:09:36: The Threat Intel which we vet and curate to make sure it's high quality as well is the information that we get when working on vulnerabilities And we're working with SAP to patch them.
00:09:51: Okay So It's a different type risk for luxury.
00:09:57: When it comes to SAP vulnerability We need to understand SAP is changing, right?
00:10:07: From one perspective.
00:10:08: There's the on-prem.
00:10:10: there's a journey to rise in the cloud.
00:10:14: In any case whether it's On-Prem Rise with Cloud or if its hybrid there's always going be component for responsibility by The client.
00:10:30: Right and on prem you have to kind of manage everything the host, that network.
00:10:35: The firewalls SAP itself whole supply chain and rise with SAP.
00:10:44: there's still components.
00:10:45: you still have to have skin in a game for protecting SAP.
00:10:51: And then the hybrid piece right?
00:10:53: You got to worry about the integrations you gotta worry about configurations.
00:10:58: however With That said some of things we've seen and some of the things that we protect, and test in pentest environments are where for instance attackers can come into SAP and find a low-privileged user.
00:11:18: They can gain entry to that low privileged user.
00:11:22: then they go ahead and escalate from that low privilege account.
00:11:25: They access full admin privileges by bypass existing SOD and access controls And we found that there might not be any activity, any logging of that activity.
00:11:41: So once that happens and these threat actors can reach this full admin privileges that can lead to exposure of client data.
00:11:51: ultra high net worth customers.
00:11:53: That's the experience for trying to protect us The brand as the trust that I spoke about.
00:11:59: right when We show up Being able to be trusted every day that continues the legacy of brands being able to Be trusted no matter where we are in a journey In technology or modernization.
00:12:17: We want to protect those private purchase histories The lists, and we don't want them leaking right?
00:12:35: being protected for SAP that's not being monitored, right?
00:12:39: Things can happen sadly and the company may not even realize it.
00:12:44: And that's why we're here today to talk about these things now.
00:12:49: That breach of client discretion Can absolutely lead to brand liability.
00:12:56: It can leads a brand damage.
00:12:58: They can lead to regulatory damage.
00:13:01: The brand mystique can be permanently eroded.
00:13:05: that took so long and, and it's hard to build throughout the years.
00:13:12: Throughout the decades... That can be lost!
00:13:16: We don't want that happen to anybody which is why we do me in my team-we do what we do because were very passionate..We wanna make the internet a safe
00:13:25: place!!
00:13:26: We wanna make companies a safe
00:13:28: places!!!
00:13:28: We do that through demonstrating our efforts within SAP security.
00:13:35: Let's keep the trust Let's keep the integrity of the data and we'll walk through what that looks like.
00:13:49: There is a risk calculation, it's risk equals probability times impact And now will give you your risk score.
00:13:58: Now You can define What Your Appetite Is For A Risk Score Which Are Comfortable With.
00:14:05: But The Important Thing Is To Understand The Threat Landscape To Understand YOUR Environment to understand if you have vulnerability management program or processes in place, as well as monitoring.
00:14:20: You want to make sure that SAP is integrated into your existing information security processes?
00:14:28: Do we wanna make sure they are taking a look at and understanding what the attack vectors looked like who threat actors are targeting SAP?
00:14:41: You want to understand the manual, as well as the automated SAP vulnerabilities that can be exploited and understand what it is that these threat actors are going after.
00:14:52: We'll double click on those.
00:14:54: Josso we wanna talk about the impact right?
00:14:59: The impact Can Be Chaotic It Can Be Epic And They Can Be Damaging.
00:15:06: So prior to twenty-twenty five.
00:15:08: when I've done Threat Briefings I've often been asked the question, well what's the real impact?
00:15:14: Onapsis research labs.
00:15:16: we do respond to incidents.
00:15:18: We do respond breaches.
00:15:20: You can't talk about those—those are confidential!
00:15:24: However, twenty-twenty five was a game changer and in Twenty-Twenty Five…we're seeing public announcements of companies that have been breached.
00:15:37: Prior to Twenty-twty-five …I would not use this phrase.
00:15:42: But as of twenty-twenty five, those public breaches.
00:15:46: Those public incidents.
00:15:48: Those Public bankruptcies they become a cautionary tale and so all of the sudden that adds more depth And that increases in ads to the passion we have.
00:16:02: make sure We disseminate timely threat intelligence To everybody because we don't want people to be an example of a cautionary tale.
00:16:18: It's not a good place to be, and in some of these instances the breaches themselves are still felt in the long tail which is remarkable in this day-and-age.
00:16:35: Okay let's go ahead into that.
00:16:38: vulnerabilities.
00:16:39: In twenty twenty five it was hands down The most epic year in SAP's history.
00:16:48: We saw a big increase in vulnerabilities and the emergence of the deserialization attack as the number one critical threat, we have a little snapshot here of November.
00:17:04: And November was pretty big deal because it led to this CVSS-TEN score at top security hardening for insecure deserialsation in SAP NetWeaver, AS Java.
00:17:20: So this java deserialization attack is big zero day.
00:17:24: it's the CVE.
00:17:26: twenty-twenty five three one three two four.
00:17:30: that was the first CVE that acknowledged This Zero Day and attempted to patch The Zero Day And In That the attackers were able to successfully compromise hundreds of companies.
00:17:48: We worked with incident response companies, we work directly with customers when they've been breached by the zero day.
00:17:58: It was a pretty big deal and it is so sophisticated!
00:18:03: And it was closed...it was being leveraged by nation-state actors from Russia and from China.
00:18:12: but ultimately there's been a couple of releases one of them that we worked intimately with SAP to make sure the root cause for this zero day was being addressed.
00:18:34: A little snapshot, a bit of chart going back throughout years... We could see in twenty-twenty five is big milestone spike and my research labs discovered forty four percent all critical hot news.
00:18:53: SAP vulnerabilities Got a great team.
00:18:57: I love my team!
00:18:59: I Love what we do, We have A lot of fun?
00:19:01: We've got A lot Of teamwork Transparency Comradery And it's Great Where We can get Together and Do the things that We love.
00:19:11: The output of That comes straight to you.
00:19:17: So this slide.
00:19:20: i like To bring up This Slide Because It Does Talk About CWE or common weakness enumeration.
00:19:32: If we take a look over the past few years, will notice that some of the weaknesses have increased?
00:19:42: Some have shifted.
00:19:44: so these weaknesses are weaknesses in this software right like missing authorization.
00:19:52: So twenty-twenty two and twenty three it was number to but in last couple and that means there might be some code, but it's not doing an authorization check.
00:20:09: There is no authorization so anyone even with a low-privileged user role can come in to run an injection attack against your SAP.
00:20:24: that can then essentially do bad things we don't want.
00:20:29: but we can see what's been the focus of these patches over the last four years at cross-site scripting.
00:20:39: It was number one in twenty, twenty three and it started to come down a little bit.
00:20:45: so that's good context to keep in mind when we take a look at twenty twenty five overall for this SAP security notes We have uh...over two hundred new an updated notes.
00:20:59: We have well over twenty-five hot news, forty two high priority notes average of three plus per month.
00:21:08: And then we kind of break that down.
00:21:10: the most patch components and vulnerability type SAP netweaver.
00:21:14: there we go we see the serialization any authorization checks yes for HANA solution manager business objects SAP commerce cross site scripting third party.
00:21:26: even like Tomcat In our contribution, we see that.
00:21:32: We love that were so embedded in with SAP that we work with finding these hot news and getting them patched before it gives the attackers the ability to find it themselves right?
00:21:49: The best thing is keep doing what you're doing and remove.
00:22:03: we're going to get into the big epic discussion about deserialization.
00:22:09: What exactly is the serialization?
00:22:13: It's taking data that's formatted in one way, putting it into another type of format so that he can be transmitted and worked with computers, then being able to reconstructed back.
00:22:27: but serialization and then deserialization, that's where this bug, this exploitation was used by these advanced attackers.
00:22:41: These nation state actors.
00:22:44: it led to being able to do a couple of different paths.
00:22:50: one path was to be able to drop a web shell through the initial entry point.
00:22:57: which Other path was to be able to execute remote code execution.
00:23:10: The interesting thing here is that when we spotted this, We started to look for other endpoints which where the number comes in When you take a look at numbers eight total deserializations seven criticals three with CVSS ten maximum severity of vulnerability can have.
00:23:31: And all of them are HTTP exploitable and they didn't have to be authenticated.
00:23:39: They were all discovered by the Anapsis Research Labs, so what that means is there's a lot different ways.
00:23:48: attackers can come into SAP through different applications or different HTTP locations but still deliver the same underlying root cause deserialization attack.
00:24:02: And it's that root cause, the serialization attack.
00:24:04: That was very hard for companies and incident responders to find because that deserialization attack doesn't leave a fingerprint on the system.
00:24:17: It doesn't even artifact what is left after.
00:24:21: did the serialisation attack as successful?
00:24:24: Is like that web shell.
00:24:26: so when this first got reported it got reported as, hey metadata uploader is the endpoint that has been attacked and look at the artifact.
00:24:37: It's a web shell.
00:24:38: so that can lead to false sense of security because didn't need understanding.
00:24:46: there was actually another format which is remote code.
00:24:50: execution may not mean any artifacts or evidence like a file, Like a web shell.
00:25:03: Okay Web application vulnerabilities the persistent attack surface.
00:25:11: So one of the most important things here to understand that when SAP is transitioning To web-based interfaces like Fiori commerce business objects this has expanded.
00:25:24: The web attacks surface significantly and That opens up cross-site scripting.
00:25:32: That opens up the SSRF, that opens up click jacking open redirects.
00:25:39: there's a lot more to manage.
00:25:41: how do you make sense of all that?
00:25:43: That's where the intelligence comes into play.
00:25:48: it's important to be able to understand the significance of these vulnerabilities and to be the new threat landscape for SAP.
00:26:10: So, for many years, Bonapsus, SAP, CISA we've been communicating to the broader audience that Thread Actors are targeting SAP.
00:26:26: again during our presentations at some of these conferences SAP was not well known but it is now and we discovered that in our chatter report, where threat actors being across a wide spectrum from the quote-unquote script kiddies who do not have the capability or understanding to craft their own exploits of vulnerabilities.
00:26:59: To advance threat actors hat can?
00:27:03: as well as nation-state actors that are well funded and well supported, and protected.
00:27:11: Chatter reveals that in twenty twenty five demonstrates on a global scale the havoc That they started to cause.
00:27:20: So there is no going back right.
00:27:22: it's here.
00:27:25: It doesn't matter if your SAP Is exposed publicly or not because these threat actors They're the same ones that come from outside of the SAP world.
00:27:39: These advanced threat actors know how to compromise IOTs, they know a zero-day in firewalls and are highly successful at getting into business enterprise environments not publicly exposed.
00:28:04: If SAP is not being managed, if it's not being monitored we see them attacking SAP and deploying ransomware holding companies to ransom because they know now that SAP manages business critical assets.
00:28:27: okay I'm gonna...I always love bringing up all the columns at once on this one where we did research in the underground.
00:28:41: I mentioned a little bit about our global threat intel network, Our Global Threat Intel Network.
00:28:48: We monitor that daily weekly monthly views...we look at what is currently under attack and What Is Currently Being Exploited?
00:28:59: So some of this information comes from The Research That We've Done In The Underground as well As the information that comes from our global threat intel network, and information that we get from working with customers.
00:29:14: In particular I want to start off with the M Trends report for twenty-twenty six states that The most frequently exploited vulnerabilities last year top of the list SAP NetWeaver.
00:29:31: this twenty twenty five three one three two four This Java serialization attack that took down hundreds of companies.
00:29:39: Then we see another ERP, Oracle e-Business Suite followed by Microsoft SharePoint.
00:29:46: So this is Another objective party well known from their own data.
00:29:55: That shows twenty twenty five was a banner year.
00:29:59: SAP has done fantastic being able to understand what the attacks are and be patch those attacks.
00:30:07: So make sure you are patching, patch-patch-pach.
00:30:13: I'm probably going to write a song about that.
00:30:15: maybe you'll hear it one day.
00:30:18: In our data we've seen over the past few years The attacks on SAP applications leveraging ransomware grow over four hundred percent.
00:30:29: We have seen when security notes get released That threat actors are exploiting them in less than seventy two hours.
00:30:38: We see the cost for black market prices for SAP exploits increased four hundred percent.
00:30:45: and When new systems are released, then they're not protected that.
00:30:49: They are discovered in compromised than less than three hours.
00:30:54: And of course all this is making news.
00:30:57: You know in prior years it might not have but it is now.
00:31:01: It is something that not only security professionals are aware of and threat actors are aware.
00:31:07: The press is highly tuned into this now as well.
00:31:12: And that, it's probably one of the things we don't want from a trust and brand management perspective.
00:31:19: so what can we ensure?
00:31:21: What can do to make sure you won't become a cautionary tale?
00:31:30: Here are some of the threat groups.
00:31:32: If I presented on these a couple years ago This list would be shorter But its not.
00:31:38: It has grown And it's grown with advanced threat actors.
00:31:41: It's grown nation state actors, with ransomware groups.
00:31:47: They're motivated to come after SAP.
00:31:50: they want to exploit the payment systems.
00:31:53: They are exfiltrating financial system and statements their pivoting.
00:32:00: a lot of these advance groups do have that knowledge capability for supply chain software outside of SAP.
00:32:11: They've simply taken their expertise and knowledge, and they're ability to adapt into the SAP landscape.
00:32:23: Shiny Hunters which was just on there one at last ones.
00:32:28: I'm going talk about them because they are an important third actor group dimension here as it comes.
00:32:33: two three-one-three-two four a big zero day.
00:32:36: first let's talk about this is a Kev catalog.
00:32:38: its the known exploited vulnerabilities catalog.
00:32:42: SISA maintains this list independently.
00:32:45: They confirm that they're CVEs, that are under active attack and exploitation.
00:32:51: some of these I believe even have a confirmation that their being used for ransomware campaigns.
00:32:58: you can visit sisa kev catalog an verify these yourselves too which is fantastic.
00:33:04: we love the scientific method.
00:33:06: We Love anybody been able to go in Verify information And this slide, you can certainly do that both with the table as well as the chart.
00:33:16: The chart is looking at the shadow server foundation's information.
00:33:20: they keep a global sensor network where they monitor what CVEs are under attack and so With the Shadow Server site What we did was we pivoted on SAP?
00:33:31: We took a look As to what their sensors were observing in twenty-twenty five.
00:33:37: You could see here Under August twenty-twenty five this peak That is directly related that blue.
00:33:46: Is directly related to three one, three two four prior?
00:33:50: To that spike there were two groups the China based and Russia based groups that had and we're exploiting The three one through two.
00:34:00: for once.
00:34:02: August came around.
00:34:03: shiny hunters released that exploit to the public And that had a cascading effect.
00:34:10: A lot of other of these CVEs were being picked up and observed as they were used to attack the sensors that Shadow Server maintains.
00:34:24: Of course, we've seen similar.
00:34:26: We like to pull in you know Other independent authorities To help validate and confirm.
00:34:34: Right, it makes sense.
00:34:35: We all live together in this global marketplace of this global commerce and It's good to share that information And get double checks.
00:34:44: The other important thing I want To mention is That In the CISA-CAV catalog A lot Of these were found by the onapsis research labs very fast pickup by the onapsis platform.
00:35:01: So we're able to help our customers very quickly because We have a research team that finds these.
00:35:09: The value of exploits they've gone up.
00:35:12: it is mind boggling That someone is looking for two hundred and fifty thousand dollars For an exploit targeting SAP remote code execution.
00:35:27: Wow You know.
00:35:32: Wow, if there's anything out There that tells you the threat actors are serious.
00:35:39: This is it.
00:35:42: Let let us put aside The fact that hundreds of companies were compromised the fact That their prices at these levels Is nuts.
00:35:54: We have a couple snapshots here.
00:35:56: There's a snapshot Here Of an exploit in the dark market SAP Secure Storage to find credentials, escalate privileges and eventually compromise another SAP system behind the first target.
00:36:15: Please be mindful that threat is real.
00:36:18: The thread is live!
00:36:19: The Thread Is Now!
00:36:25: Mandiant also provided a time-to-exploit trends affecting business applications.
00:36:33: like we've seen in our own global threat intel network is that the time to exploit does continue to decrease.
00:36:42: So, Threat Actors are getting faster and faster to be able to exploit vulnerabilities And more importantly older vulnerabilities are still a target.
00:36:55: Let me go back this prior slide.
00:36:59: We'll notice that bottom one CVE- Yes, we see that still under attack today.
00:37:08: So that leaves me to believe We have businesses out there That are not running a vulnerability management program Sadly until after they get breached?
00:37:23: We don't want that to happen which is why we do these webinars.
00:37:29: and in the case of recon Which Is what we discovered And was one Of The critical alerts sisa issued We see active exploitation in less than seventy-two hours after the patch was released.
00:37:46: Okay, The cautionary tale we don't want anyone to end up as a cautionary tail Here.
00:37:56: we have A large beverage manufacturing company that actually filed in court records, which you can do a search.
00:38:06: You can find the court records yourselves.
00:38:08: these snapshots on the left there are actual snapshots of the Court filings where the CEO was filing for bankruptcy protection due to an SAP security breach.
00:38:24: we don't want SAP going down during fashion week or holiday season You know, that can mess with client orders not being processed.
00:38:35: Financial reporting becomes impossible.
00:38:39: It's Not only an incident it becomes a brand crisis right?
00:38:44: It's going back to that relationship.
00:38:47: Fundamentally we want to maintain the integrity of That product of the brand and of the relationship Hundreds of companies compromised.
00:39:01: here is a brief little time when We've talked a little bit about this.
00:39:05: one thing.
00:39:06: I want to highlight and emphasize is that we were the only company on the planet That captured The actual attack.
00:39:17: so when we understood that this was happening?
00:39:21: um, we dove into that attack.
00:39:24: we reverse engineered it.
00:39:26: we understood there was a gadget chain involved.
00:39:31: We discovered that it wasn't only dropping of a web shell, but actually having payload.
00:39:39: you can run remote code execution.
00:39:41: Once we started to deconstruct this attack, we partnered very quickly and closely with SAP not just patching the other endpoints.
00:40:01: anyone who delivers a product doesn't understand what the root cause is, it can step into a whack-a-mole situation where an endpoint pops up that's being used to leverage the root Cause.
00:40:16: You close down at end point but then there are other Endpoints That Can Be Found.
00:40:21: So...that continues to address each and every endpoint as they're discovered But It Does Not Underline The Root Cause.
00:40:31: our work led to being able to understand the root cause for SAP and for SAP to issue the patch.
00:40:41: As a matter of fact, if you go to SAP's website and you look up the credits to researchers for twenty-twenty five big thank you in much love and gratitude to SAP for giving us wonderful shout out wonderful credit.
00:41:01: Epic three one, three two four zero day.
00:41:05: Love that we can work together.
00:41:09: timeline for this attack the Three One, Three Two Four.
00:41:12: so The initial probes were observed at the beginning of twenty-twenty five and when This first started to get announced the thought was That this Was a metadata uploader but from start To about August it was Observed as being used by China-based threat actors, as well as Russia based threat actors.
00:41:38: Very limited group and of course we had it but our goal was to make sure we understood it in worth with SAP to get it patched.
00:41:46: then Of course come August We see shiny hunters releasing it.
00:41:54: now As we see august fifteenth released on the shiny hunter's telegram by shiny shiny hunters they release the fully functional exploit.
00:42:08: It supports both modes, direct remote code execution as well as the web shell deployment and it also supported two latest versions of NetWeaver seven dot five in seven four .It does have a sophisticated post exploitation And it does make use of custom tooling very much targeted specific SAP assets.
00:42:35: so there's of deep understanding by these threat actors.
00:42:41: They know what they're doing and they know what their targeting, all that's been released publicly.
00:42:46: so when we talk about the chatter report in a big spectrum of attackers those script katies can take this to do heavy damage.
00:42:58: let's go into the exploit details.
00:43:01: I've got couple things here highlighted like why so serial?
00:43:04: That is de-serialization framework the attackers are using in their exploit.
00:43:12: Here's a snippet where they're looking at specific versions like seven point five, if it's seven point-five, it executes a certain line of code and then Of course we see at the end credits out to shiny hunters And you're making some comments in there too because that's what they do.
00:43:33: but That is an example of small little example of the exploit that was released by Shiny Hunters, that anyone can access.
00:43:44: Another cautionary tale... That exploit code we just looked at briefly?
00:43:49: Snippets!
00:43:51: Shiny Hunter's They're the ones who claim responsibility for attack and takedowns a global manufacturing company.
00:44:01: This attack was so far-reaching it drove GDP down into negative territory.
00:44:08: Tens of thousands employees were furloughed companies in the supply chain went out of business.
00:44:15: And as a matter fact, it has a long tail—it's still reverberating to today where I've met people that have their vehicles from this global manufacturing company and they're waiting for safety components which is mind-boggling!
00:44:35: It not only impacted all of these businesses in the global economy for the UK, but an impact it consumers even into April because they're still not getting their safety products or components that go into.
00:44:53: The thing that they have from this manufacturing company?
00:44:58: This is worst case scenario.
00:45:03: I've been asked can you show examples?
00:45:07: As well as the bankruptcy filing, these are the impacts that I can now talk about because they're very public.
00:45:15: It is gone out of the hands of these companies and i feel for them...I do!
00:45:19: I've been an incident responder.
00:45:21: it's tough.
00:45:22: you set aside time with family You set aside holidays And you are up online in late oil to try and understand what's happening.
00:45:31: So I feel for everybody there.
00:45:33: I Feel For Anybody Who Gets An Incident Especially A Big Breach.
00:45:39: The thing though is that we can use this as a poignant reminder.
00:45:45: That anyone can be targeted, no one is safe and there's things that we could do to prepare for it.
00:45:59: This is from Telegram Channel.
00:46:02: We look at Shodam A. Shodan is another security entity out here that provides information Information on IPs.
00:46:12: This was tied to an SAP portal out in Coventry.
00:46:21: And this is a snapshot of threat actor group that has logged into a business operation and it's showing information on one of the hosts within The Enterprise, we see a lot.
00:46:44: Let's get into the fundamental risks to luxury brand equity.
00:46:48: a lot of what this says is That things can happen, you know we.
00:46:58: it's all about the relationship.
00:47:00: It's about relationships internally where security practitioners take an objective view of the threat landscape.
00:47:09: You work with your architects, you work with Your Security Operations Center ,you Work With Your IT, you Work With Basis...You Work With The Business..You Understand What The Critical Points Are For Your Business....What are You Doing To Protect All Of That?
00:47:24: What Are You Doing to Monitor for all that?
00:47:26: Because If You Don't!
00:47:28: The Heists Can Happen Right?
00:47:30: You can Have Ghost Inventories For Counterfeiters Entering The Great Markets You can have pricing manipulation, you can have disruption during peak season.
00:47:40: Oh we don't want disruption during fashion week or holidays.
00:47:45: that can lead to tons of loss for revenue and lasting damage for partnerships.
00:47:55: Yeah I can say enough.
00:47:57: there's been a lot of lessons learned over twenty-twenty five by a lot.
00:48:04: the data has been breached.
00:48:05: We don't want ultra high net worth client registries breached, we wanna protect that privacy.
00:48:11: it's about that relationship.
00:48:18: Compliance myths.
00:48:21: there is being able to do the compliance check and then their security check right?
00:48:27: So you could potentially pass the compliance checks but doesn't make really ready for security audits.
00:48:38: It's important to understand that there is a distinction between the two because compliance checks says, okay you're doing things we need.
00:48:47: These are thresholds but never want to maintain them and go last mile in where threat actors reside That place they know have best chance of getting through systems.
00:49:06: that we want to make sure you are ready for real-time monitoring, that you have a continuous vulnerability management assessment program aided and informed by curated quality threat intel.
00:49:26: Please make sure your SAP is integrated into existing SOXs in incident response.
00:49:40: This is fantastic for content dev teams that work as security practitioners, this is fantastic.
00:49:47: For incident responders because we can start to map what these attacks look like through the MITRE attack framework.
00:49:58: so We could see here whether or through external third-party or employee That some of these TTPs are initial access valid accounts, default accounts or exploit public-facing applications.
00:50:11: Or it could be a spearfishing link or trusted relationship right?
00:50:15: It can also be a valid account but once that initial access is taken it could lead to privilege escalation.
00:50:23: we found a lot of vulnerabilities where thats possible.
00:50:26: We've stepped into environments ourselves and pen tested have been able successfully escalate privilege.
00:50:33: It's better to have us do it than an actual threat actor, because if its us we'll work with you To ensure You understand what the thread is in your environment and to get it protected.
00:50:46: Especially If you're not using an application that Is informed by our threat intelligence like onapsis platform And That can lead to exfiltration of data In the impact.
00:50:58: Yeah could be catastrophic.
00:51:03: I'll kind of go through these here a little bit quicker, but you can see with the little bit more detail about initial access and their descriptions.
00:51:13: This is something that you can absolutely verify on your own.
00:51:17: You could go to Mitre Attack, you could look up Initial Access ,you could look at The Techniques .You Could Look At The Descriptions.
00:51:29: Here's some for Prilogescalation Lateral Movement Persistence.
00:51:35: Let's take a look at persistence.
00:51:37: Once certain functionalities or authorizations have been achieved, attackers can create high-privileged users with well known powerful profiles such as SAP AWM.
00:51:49: Threats there!
00:51:54: Some more... some outcomes right?
00:51:56: The exfiltration the impact ransomware incidents can affect SAP applications and includes the encryption of SAP information.
00:52:04: And we see it.
00:52:06: We See It Happening Without V With Lock Bit.
00:52:11: We've seen the impact of financial theft.
00:52:14: There was a company that had that CVE from twenty ten be exploited and they lost millions Of dollars through payment systems, so it happens.
00:52:32: Okay Let's get to some additional information.
00:52:36: here we talk about challenges That do not go away in this shared responsibility model with rise.
00:52:45: There's components that SAP manages, the network, the infrastructure.
00:52:50: The operating system and database management.
00:52:53: yet there still a whole lot has to be owned by customers business data users configurations.
00:53:02: those are all important.
00:53:04: continue monitor.
00:53:05: please understand it is shared right share security model.
00:53:11: there's components that need to be handled by the customer.
00:53:14: Now, we have a fantastic quote from SAP CISO.
00:53:18: SAP delivers highly secure and compliant cloud infrastructure.
00:53:22: enabling customers to focus solely on securing their SAP applications and data going to rise means you still need to maintain SAP security.
00:53:38: We help streamline these areas of responsibilities under rise.
00:53:44: So you have access to me, it can reach out to me.
00:53:50: we could have follow-up meetings on anything he like.
00:53:54: our work or output goes right into an apps is platform.
00:53:58: so if you want to have the feeling and a certainty in the trust rate always back to trust.
00:54:06: do what.
00:54:06: I have the trust that we've got your back on apps as research labs in the lap of Onapsis platform.
00:54:14: It's like having Onapses research labs, researchers there with you on demand around-the-clock being able to assess your environment be able to defend your environment.
00:54:27: So that's really one of the big takeaways right?
00:54:32: You have to manage SAP security under rise and we can be partners too.
00:54:42: together SAP and Onapsis provide enhanced security for rise with SAP.
00:54:48: That continues the quote from Roland, SAP's global CISO for SAP Enterprise Cloud Services in Rise.
00:55:02: Oh big thing.
00:55:04: here we are The only SAP endorsed app on apps this platform.
00:55:16: that's a huge one.
00:55:17: We've put a lot of work and love an effort to be able get there and to earn SAP's trust.
00:55:24: We understand trust, we understand brand, we understanding
00:55:29: relationships.".
00:55:36: I mentioned control assesses in Defend.
00:55:38: Well actually didn't mention control blah!
00:55:40: I'm mentioning it now.
00:55:42: Control scans for code right?
00:55:46: It helps with DevSecOps.
00:55:48: Assess is your vulnerability management component.
00:55:54: So all of this comes together in a unified SAP application attack surface management.
00:56:00: It's powered again by the Onapsis Research Labs, your ace up your sleeve so to speak.
00:56:09: why?
00:56:09: This matters for our luxury conglomerate.
00:56:13: In a multi-maison visibility it provides a single platform view across SAP instances every brand Every region every deployment model under a unified attack surface Management.
00:56:27: It's powered by my team's threat intelligence.
00:56:30: Its real time and it feeds right into the platform.
00:56:34: we go back to that experience, too That relationship?
00:56:37: It protects it.
00:56:39: We're all about protecting.
00:56:40: you were all About protecting customers that use SAP And its secures your digital transformation as You move to rise or S for HANA Actions to take today.
00:56:56: know Your attack surface.
00:56:57: we've talked manage vulnerabilities with trusted and vetted threat intelligence, we've talked about that.
00:57:05: As well as integrate SAP into your security programs they're all important actions that you can take.
00:57:13: if You have already done so please give yourselves a round of applause.
00:57:16: I am proud to for doing it And i'm proud of you For being able To get this far With me in This journey Of relationships.
00:57:25: Please do yourself A favor And you know, thank you.
00:57:31: I appreciate for being here with me on this journey.
00:57:35: You can contact me anytime.
00:57:37: i Can be your partner.
00:57:39: Here's some helpful resources our github.
00:57:43: We have released open source tools For things like three one three two four in addition to the protection that we Have in napsis platform?
00:57:53: We have blogs you can look at or threat research and again i'm available.
00:57:58: You can find me on LinkedIn, Paul Ladansky.
00:58:02: You can reach out to me here at Onapsis.
00:58:04: I love what i do!
00:58:05: I Love our teams and I'd love a chance To be able to meet you And work with you.
00:58:13: Thank you
00:58:17: All right.
00:58:18: um thanks paul for those insights.
00:58:22: We've received several questions and I know there's A lot to unpack Here.
00:58:26: so let just go For one Right now and see because of we have the time constraints.
00:58:32: But Paul, somebody asked how do we convince our teams that monitoring is important if we've never been breached?
00:58:46: That's a really good question.
00:58:48: And that's the question I get all of time in prior threat briefings and my answer back then was you gotta trust us.
00:58:59: We have gone to incidents investigations and forensics.
00:59:10: It's hard to believe that SAP is gonna get targeted when people really didn't know about SAP outside of SAP, but twenty-twenty five changed everything.
00:59:23: SAP is now infiltrated by those well equipped, well understood very smart threat actor groups everything outside of SAP and now have a focus on SAP.
00:59:40: So especially in the luxury brand, it is so important brand to relationship that customer journey experience.
00:59:54: That best thing we can do for ourselves To demonstrate continued care And love For these relationships with brand and with customers, is to show that we still have the same verve.
01:00:08: That we apply that same verver...that we apply this passion as we do for our brand....that we use SAP.
01:00:20: Protecting SAP IS protecting the brand!
01:00:24: Protecting and monitoring making sure you understand what these attacks are when they're happening.
01:00:31: to make sure you understand what the vulnerabilities and the patches are when they get patched, to help you prioritize them.
01:00:39: That's applying the same zest-and-zeal that shows your commitment to the brand into the experience because SAP helps manage that brand.
01:00:51: so not managing SAP in a secure practice we've seen in twenty twenty five exposes companies a place where no one wants to be, and that's the cautionary tale.
01:01:04: So please my hope is you depart from this presentation knowing security practice in managing SAP is relationship practice.
01:01:21: it's brand protection management process.
01:01:27: more than saying oh there something going on over here?
01:01:33: We're protecting our brand.
01:01:35: We are protecting the customer journey and that means we absolutely have to protect some of the core foundational components for that, being SAP.
01:01:49: All right thanks Paul so much!
01:01:52: So...we had end on webinar today.
01:01:56: For any other questions in chat will be reaching out individually.
01:02:01: get those answered.
01:02:03: Also, just a brief reminder to everyone listening that this session has been recorded and the link of recording will be emailed.
01:02:11: And with that thanks again our speaker Paul for joining us in this briefing have.