Artwork

内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

SaaS Exposed: Unmasking Cyber Risks in Cloud Integrations

39:18
 
分享
 

Manage episode 412982150 series 3486243
内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Luke Jennings, VP of Research & Development at Push Security joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Luke explains his recent presentation on a new SaaS cyber kill chain, exploring how attackers might target modern organizations heavily reliant on cloud and SaaS services, even when traditional infrastructure is minimal. The latest kill chain involves developing attack techniques specific to this environment, covering topics like lateral movement without conventional network infrastructure and adapting known techniques such as password guessing attacks to the SaaS landscape. Luke, Wendy, and Nic discuss the complexities of SaaS security, the intricacies of evil twin integrations, detection challenges, mitigation strategies, and the overall impact of these security issues on organizations.

In This Episode You Will Learn:

  • Identifying malicious activities and understanding normal application behavior
  • The importance of having structured methodologies for approving SaaS app usage
  • Challenges organizations face in detecting and preventing SaaS application threats

Some Questions We Ask:

  • How can an organization create alerts for new, unknown SaaS app integrations?
  • What happens when a SaaS app integration is duplicated by an attacker?
  • Would having a structured methodology for SaaS app usage help minimize risk?

Resources:

View Luke Jennings on LinkedIn

View Wendy Zenone on LinkedIn

View Nic Fillingham on LinkedIn

Related Microsoft Podcasts:

Discover and follow other Microsoft podcasts at microsoft.com/podcasts


Hosted on Acast. See acast.com/privacy for more information.

  continue reading

37集单集

Artwork
icon分享
 
Manage episode 412982150 series 3486243
内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Luke Jennings, VP of Research & Development at Push Security joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Luke explains his recent presentation on a new SaaS cyber kill chain, exploring how attackers might target modern organizations heavily reliant on cloud and SaaS services, even when traditional infrastructure is minimal. The latest kill chain involves developing attack techniques specific to this environment, covering topics like lateral movement without conventional network infrastructure and adapting known techniques such as password guessing attacks to the SaaS landscape. Luke, Wendy, and Nic discuss the complexities of SaaS security, the intricacies of evil twin integrations, detection challenges, mitigation strategies, and the overall impact of these security issues on organizations.

In This Episode You Will Learn:

  • Identifying malicious activities and understanding normal application behavior
  • The importance of having structured methodologies for approving SaaS app usage
  • Challenges organizations face in detecting and preventing SaaS application threats

Some Questions We Ask:

  • How can an organization create alerts for new, unknown SaaS app integrations?
  • What happens when a SaaS app integration is duplicated by an attacker?
  • Would having a structured methodology for SaaS app usage help minimize risk?

Resources:

View Luke Jennings on LinkedIn

View Wendy Zenone on LinkedIn

View Nic Fillingham on LinkedIn

Related Microsoft Podcasts:

Discover and follow other Microsoft podcasts at microsoft.com/podcasts


Hosted on Acast. See acast.com/privacy for more information.

  continue reading

37集单集

所有剧集

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南