
SaaS apps are vulnerable too!!! (ServiceNow Exploitation)
Source: YouTube · John Hammond · published Nov 13, 2024 · 29:06
The video explores SaaS security challenges, highlighting how attackers can maintain persistence in platforms like ServiceNow and emphasizing the shared responsibility model between vendors and customers for securing cloud applications 0:36.
Key Takeaways:
• SaaS security suffers from unclear ownership - platform admins, security teams, and developers often don't know who's responsible for securing third-party applications 1:40
• In the shared responsibility model, vendors fix core vulnerabilities while customers are responsible for addressing misconfigurations they introduce 2:42
• Attackers can maintain persistence in SaaS platforms by creating hidden users, hooks that modify database queries, and scheduled scripts that recreate backdoors if deleted 6:48
• Thousands of organizations had misconfigured access controls exposing sensitive internal data through ServiceNow knowledge bases 21:00
• ServiceNow took the unprecedented step of intervening to fix customer misconfigurations, marking a shift in vendor responsibility 22:48
The conversation underscores the evolving landscape of SaaS security where both vendors and customers must collaborate to address sophisticated threats 23:32.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Al righty hey everyone thank you so much for tuning in and look I'm super excited get to chat with a new friend today Aaron Aaron Castello hey one of the researchers doing SAS security over at app Omni and I'm very excited because this is a whole new world for me I don't know much of SAS security because I'm normally just coming from the endpoint world but I think hey it's a whole new different ball game and Aaron it's great to see you my friend I hope things are well but I'd love to learn what you're up to these days and I don't know what you got in the works for us here yeah absolutely thank you so much for for having me on I'm really excited to introduce you to this exciting new space of s security and I think in the interest of starting at the beginning of the story right we can start …