SaaS apps are vulnerable too!!! (ServiceNow Exploitation)

SaaS apps are vulnerable too!!! (ServiceNow Exploitation)

Source: YouTube · John Hammond · published Nov 13, 2024 · 29:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video explores SaaS security challenges, highlighting how attackers can maintain persistence in platforms like ServiceNow and emphasizing the shared responsibility model between vendors and customers for securing cloud applications 0:36.

Key Takeaways:
• SaaS security suffers from unclear ownership - platform admins, security teams, and developers often don't know who's responsible for securing third-party applications 1:40
• In the shared responsibility model, vendors fix core vulnerabilities while customers are responsible for addressing misconfigurations they introduce 2:42
• Attackers can maintain persistence in SaaS platforms by creating hidden users, hooks that modify database queries, and scheduled scripts that recreate backdoors if deleted 6:48
• Thousands of organizations had misconfigured access controls exposing sensitive internal data through ServiceNow knowledge bases 21:00
• ServiceNow took the unprecedented step of intervening to fix customer misconfigurations, marking a shift in vendor responsibility 22:48

The conversation underscores the evolving landscape of SaaS security where both vendors and customers must collaborate to address sophisticated threats 23:32.

Sources:

  • 0:36 Introduction to SaaS security challenges
  • 1:40 Discussion on unclear ownership of SaaS security
  • 2:42 Explanation of shared responsibility model
  • 6:48 Demonstration of persistence

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Al righty hey everyone thank you so much for tuning in and look I'm super excited get to chat with a new friend today Aaron Aaron Castello hey one of the researchers doing SAS security over at app Omni and I'm very excited because this is a whole new world for me I don't know much of SAS security because I'm normally just coming from the endpoint world but I think hey it's a whole new different ball game and Aaron it's great to see you my friend I hope things are well but I'd love to learn what you're up to these days and I don't know what you got in the works for us here yeah absolutely thank you so much for for having me on I'm really excited to introduce you to this exciting new space of s security and I think in the interest of starting at the beginning of the story right we can start …