What's new arround internet

Last one

Src Date (GMT) Titre Description Tags Stories Notes
onapsis.webp 2017-07-11 15:25:27 SAP Security Notes July 2017: Patched Denial Of Service Vulnerability affecting all SAP Platforms (lien direct) Today is the the second Tuesday of July and as our readers already know that today SAP released its monthly Security Notes. Here is our monthly report on how to improve your ERP security and take care of your most critical information. Today SAP released 16 new security notes, summing up to a total of 23 taking into account the ones published after second Tuesday last month. For the third month in a row there aren't any notes tagged as Hot News.SAP, SAP Security Notes, SAP vulnerabilities, SAP Denial of ServiceSAP Security NotesSebastian Bortnik07/11/2017
onapsis.webp 2017-07-06 19:21:34 (Déjà vu) Protecting Oracle E-Business Suite: Password Policy: Reducing the Attack Surface (lien direct) This is the fourth consecutive blog post in our series on how to make Oracle E-Business Suite more secure. In this post, we will focus on reducing the attack surface - something that is a critical component for any successful information security strategy. The more you can reduce the components that are exposed to attackers (and to vulnerabilities), the more you can focus on keeping your exposed systems secure.Oracle, Oracle Security, Oracle vulnerabilityResearchMatias Mevied07/06/2017
onapsis.webp 2017-07-06 19:21:34 (Déjà vu) Protecting Oracle E-Business Suite: Reducing the Attack Surface (lien direct) This is the fourth consecutive blog post in our series on how to make Oracle E-Business Suite more secure. In this post, we will focus on reducing the attack surface - something that is a critical component for any successful information security strategy. The more you can reduce the components that are exposed to attackers (and to vulnerabilities), the more you can focus on keeping your exposed systems secure.Oracle, Oracle Security, Oracle vulnerabilityResearchMatias Mevied07/06/2017
onapsis.webp 2017-06-29 19:22:51 Protecting Oracle E-Business Suite: Password Policy (lien direct) For a third week in a row, we're providing you with best practices for securing your Oracle E-Business Suite implementation. Today, we are going to talk about a common topic: password security. When it comes to password policy, the first thing that probably comes to mind is having a secure password. That is why in addition to all network security layers, it is very important to have a proper password policy, along with a users list and groups so to follow a guideline of how passwords are formed.Oracle, Oracle EBS, Oracle E-Business Suite, Oracle EBS SecurityResearchSebastian Bortnik06/29/2017
onapsis.webp 2017-06-23 15:01:47 Protecting Oracle E-Business Suite: Hashed Passwords (lien direct) Last week, we begin a blogpost series with the objective of reviewing Oracle E-Business Suite Security. The first publication detailed how to activate the Server Security Feature, and in today's post we will focus on password hashing. We will analyze the different types of hashing and how it is implemented in Oracle E-Business Suite.ResearchMatias Mevied06/23/2017
onapsis.webp 2017-06-15 17:42:10 Protecting Oracle E-Business Suite: Activate Server Security (lien direct) As most of our regular readers may know, the Onapsis Research Labs have been working on developing Oracle Security for several months. We've done this by updating our readers with analysis on quarterly patch updates, and to date have released over one hundred advisories for this platform. In our continous goal to provide the industry with greater resources to secure their business critical applications, starting today we will be publishing a series of weekly blog posts focusing on different areas of protecting Oracle E-Business Suite. Oracle, Oracle EBS, Oracle E-Business SuiteResearchSebastian Bortnik06/15/2017
onapsis.webp 2017-06-13 15:33:42 SAP Security Notes June 2017: Information Disclosure and Denial of Service (lien direct) As with the second Tuesday of every month, today SAP released its monthly Security Notes to keep your SAP infrastructure secure. This month, SAP published 18 new security notes, and released 11 security notes that were published after May 9th (last patch tuesday), totaling 29 notes that will be analyzed in this post. For the second month in a row there aren't any notes tagged as Hot News; the most critical risk category that SAP has catalogued for newly discovered vulnerabilities.SAP, SAP Security Notes, SAP vulnerabilities, SAP Denial of ServiceSAP Security NotesSebastian Bortnik06/13/2017
onapsis.webp 2017-05-15 19:55:29 How to know if your SAP systems are affected by WannaCry (lien direct) Implement newly released SAP Security Note: 2473454 to confirm your SAP systems are protected. ResearchPablo Artuso05/15/2017 Wannacry
onapsis.webp 2017-05-09 14:43:49 SAP Security Notes May 2017: Military and Defense Solutions (lien direct) As with the second Tuesday of every month, today SAP released its monthly Security Notes to keep your SAP infrastructure secure. This month, SAP published 14 new Security Notes with only one note tagged as High Priority. However, of these 14 notes, four of them are updates to previous publications. Based on the number of fixed vulnerabilities, and the criticality of each, it's safe to say that this is not a critical patch day for SAP compared to previous months.SAP Security NotesSebastian Bortnik05/09/2017
onapsis.webp 2017-04-19 17:48:29 Another Record Breaking Oracle CPU - April 2017 (lien direct) Yesterday, Oracle released its quarterly security patches and what a record breaking CPU it was! With close to 300 published patches, this marks the highest number of patches released to date for any CPU. This further validates the trend we have seen in previous CPU's which is  to correct more vulnerabilities in Oracle products due to increased research submissions targeting different Oracle products.Oracle, Oracle CPU, Oracle vulnerability, Oracle advisoryResearchMatias Mevied04/19/2017
onapsis.webp 2017-04-13 18:47:38 How the Proposed OWASP TOP 10 Changes Would Affect SAP and Oracle (lien direct) While only in release candidate form, the current proposed changes to the OWASP Top 10 Application Security Risks provide clear guidance for any enterprise that needs to secure and protect their critical enterprise business applications. In general, the OWASP Top 10 and these two additions can be directly applied to an approach and methodology for securing ERP based business applications and systems.ResearchAlex Horan04/13/2017
onapsis.webp 2017-04-11 16:26:39 (Déjà vu) SAP Security Notes April 2017: JURASSIC SAP is Back (lien direct) As with the second Tuesday of every month, today SAP released its monthly Security Notes. This month, SAP published 19 new Security Notes, as well as a summary of 28 different notes including ones published last patch Tuesday. For a second month in a row, there's a 'Hot News' item relating to Remote Code Execution. SAP Security NotesSebastian Bortnik04/11/2017
onapsis.webp 2017-04-11 16:26:39 (Déjà vu) SAP Security Notes April 2017: Vulnerabilities Affecting SAP TREX (lien direct) As with the second Tuesday of every month, today SAP released its monthly Security Notes. This month, SAP published 19 new Security Notes, as well as a summary of 28 different notes including ones published last patch Tuesday. For a second month in a row, there's a 'Hot News' item relating to Remote Code Execution. SAP Security NotesSebastian Bortnik04/11/2017
onapsis.webp 2017-04-07 12:52:22 SAP Notes March Review: FAQ about High Priority Notes (lien direct) We are just a few days away from the release of SAP's April Security Notes. Since this past month included some of the most critical notes we have seen to date for SAP, we'd like to review a few things we saw in March to ensure we have everything fully covered before heading into April. It was an interesting month for SAP Security, as findings from our Researchers yielded the second 'Hot News' note to date for 2017. In addition however, there were some other important vulnerabilities published in March that were tagged as 'High Priority' and should be mitigated if present in SAP systems.SAP Security NotesSebastian Bortnik04/07/2017
onapsis.webp 2017-03-14 07:52:54 SAP Security Notes March 2017: Onapsis Helps Secure Critical Bugs in SAP HANA (lien direct) Today SAP release its monthly Security Notes, as they do the every second Tuesday of every month. Among the 27 SAP Security Notes published today, 5 of them are related to SAP HANA, and were originally reported by Onapsis Research Labs. One of them, note #2424173, is the only SAP Security Note tagged as Hot News this month as it solves several vulnerabilities in the Self Service component (disabled by default) that can allow an attacker to fully compromise the SAP HANA system without the need of credentials.SAP Security Notes, SAP Security, SAP HANA, SAP HANA Security, SAP HANA 2.0SAP Security NotesSebastian Bortnik03/14/2017
onapsis.webp 2017-03-10 15:19:31 (Déjà vu) 2017 North American Roadshow Series - Coming to a City Near You! (lien direct) I'm pleased to announce that today we're kicking off our third annual Onapsis Roadshow series in North America. With the major developments SAP cybersecurity has seen over the past few months, I feel like our roadshows could not have come at a better time.CorporateMariano Nunez03/10/2017
onapsis.webp 2017-02-14 16:04:19 SAP Security Notes February 2017: Turning up the Volume (lien direct) In this month's SAP Security Notes, it's noticeable that the priority of the majority of security notes are higher compared to previous month. SAP, SAP Security Notes, SAP vulnerabilities, CVSS, SAP SecuritySAP Security NotesEmiliano Fausto02/14/2017
onapsis.webp 2017-01-17 17:55:33 Oracle CPU for January 2017 Breaks New Record (lien direct) In this month's post we will analyze the January 2017 Oracle Critical Patch Update (CPU) and how it relates to Oracle Business Critical Applications. This CPU is special because the number of vulnerabilities fixed sets a new record for the amount of vulnerabilities fixed in a single CPU for Business Critical Applications. At Onapsis, we believe there are two main factors that contribute to this record breaking number of vulnerabilities in a single CPU. These two factors are the Researchers and of course, Oracle itself.Oracle, Oracle CPU, Oracle vulnerability, Oracle advisoryResearchMatias Mevied01/17/2017
onapsis.webp 2017-01-12 14:37:46 Announcing the Onapsis SAP HANA Security Resource Center (lien direct) SAP HANA evolved a lot in 2016, as did security focused on this critical platform. The year ended with the release of the “new generation” version, SAP HANA 2. Starting in early December, customers have been able to upgrade to this new version that SAP explains as big enough not to call it SAP HANA SP13. This new release is another testament to the success of SAP HANA adoption and will continue to increase the amount of customers that are moving to the world of the SAP in-memory database.ResearchSebastian Bortnik01/12/2017
onapsis.webp 2017-01-10 17:54:29 SAP Security Notes January 2017: Continued Security Focus on SAP for Defense (lien direct) So, 2017 begins... and the first Patch Day has arrived. Today, SAP published its first Security Notes post of the year, making a total of 24 notes (21 published today) since the last Security Notes Tuesday in December. The amount of security corrections for each month starts consistent with last year (keeping the average of 25 SAP Security Notes per month). Today SAP published, for the second month in a row, SAP Security Notes for SAP ERP Defense Forces and Public Security.SAP Security NotesSebastian Bortnik01/10/2017
onapsis.webp 2017-01-06 18:52:02 SAP Security Notes 2016: A Year in Review (lien direct) Since its foundation, the Onapsis Research Labs have been actively helping SAP improve its security by researching and reporting system vulnerabilities. On the second Tuesday of each month, the Onapsis Research Labs publishes a detailed analysis of the latest SAP security notes. This helps to better assist our customers secure their SAP systems from the latest threats, and helps to ensure that our products are designed to continuously detect new vulnerabilities.SAP Security, SAP Security Notes, SAP vulnerabilitiesResearchSebastian Bortnik01/06/2017
onapsis.webp 2016-12-22 16:50:57 Now Announcing: Splunk Integration with OSP! (lien direct) As the Onapsis Security Platform continues to become more widely adopted throughout global enterprises, we have received an overwhelming number of requests to integrate OSP with our customer's existing SIEM solutions. Based on these requests, we are excited to announce that we have officially launched an integration with Splunk Enterprise. This marks our second SIEM integration following IBM's QRadar which we launched earlier this month.  ProductAlex Horan12/22/2016
onapsis.webp 2016-12-13 18:31:02 (Déjà vu) Onapsis Research Labs First to Help Discover and Fix Vulnerabilities in SAP HANA SPS12 - SAP Security Notes December 2016 (lien direct) Today SAP published 23 Security Notes, making a total of 32 notes since last second Tuesday of November, considering several notes that were published outside of the normal publishing schedule. As with every month, the Onapsis Research Labs have an impact on how SAP Security evolves. This month, 6 SAP Security Notes were reported to SAP by our researchers Sergio Abraham, Nahuel Sanchez and Emiliano Fausto (all of them recognized in SAP Webpage).SAP, SAP Security Notes, SAP HANA, SAP Security, SAP cybersecuritySAP Security NotesSebastian Bortnik12/13/2016
onapsis.webp 2016-12-13 18:31:02 (Déjà vu) Onapsis Research Labs First to Find Vulnerabilities in SAP HANA SPS12 - SAP Security Notes December 2016 (lien direct) Today SAP published 23 Security Notes, making a total of 32 notes since last second Tuesday of November, considering several notes that were published outside of the normal publishing schedule. As with every month, the Onapsis Research Labs have an impact on how SAP Security evolves. This month, 6 SAP Security Notes were reported to SAP by our researchers Sergio Abraham, Nahuel Sanchez and Emiliano Fausto (all of them recognized in SAP Webpage).SAP, SAP Security Notes, SAP HANA, SAP Security, SAP cybersecuritySAP Security NotesSebastian Bortnik12/13/2016
onapsis.webp 2016-11-08 18:11:14 SAP Security Notes November 2016 – The Return of OS Command Injection (lien direct) Today SAP published 13 Security Notes, two of which were tagged as 'Hot News' items. These two bugs were discovered a few months ago by the Onapsis Research Labs and represents the most critical updates to patch in order to properly protect your SAP Systems.SAP Security NotesEmiliano Fausto11/08/2016
onapsis.webp 2016-10-19 20:17:42 Oracle Publishes 253 New Vulnerabilities in October 2016 CPU (lien direct) Yesterday, Oracle released its quarterly Critical Patch Update (CPU) to provide customers with detailed information about the latest vulnerabilities affecting Oracle business critical applications. This post will help Oracle customers better understand and prioritize the implementation of patches and testing of vulnerabilities on these systems within their organization. In this CPU, Oracle published 253 patches which affect 76 different Oracle products. We will analyze the Critical Patch Update and then will focus on the Oracle E-Business Suite vulnerabilities.ResearchMatias Mevied10/19/2016
onapsis.webp 2016-10-11 18:04:58 Switchable Authorization Checks: SAP Security Notes October 2016 (lien direct) Today, SAP released their monthly security notes. This month, there are 23 new SAP notes that contain new switchable authorization checks in RFC, and 7 SAP Notes for missing authorization checks. This month's security notes also includes 29 note updates from previously published security notes.SAP Security NotesJulian Rapisardi10/11/2016
onapsis.webp 2016-10-04 19:55:46 Moving SAP to the Cloud? Let Security Be On Your Side (lien direct) In today's evolving IT landscape, companies are constantly planning their next steps when it comes to business-critical application security. Specifically, around their SAP environment which supports core business processes for some of the world's largest organizations. When it comes to migrating SAP solutions to the cloud, different roadmaps are regularly being assembled and developed in order to properly transfer solutions that were traditionally supported by on premise SAP systems to a diverse range of cloud offerings provided by SAP.ResearchMatias Mevied10/04/2016
onapsis.webp 2016-09-21 16:09:24 Onapsis Publishes Advisories for Cross Site Scripting and OS Command Injection Vulnerabilities (lien direct) Today, the Onapsis Research Labs released 14 advisories for SAP and 6 for Oracle E-Business Suite. All of the SAP advisories pertain to SAP NetWeaver - the technical integration platform on top of which enterprise and business solutions are developed and run. Half of these advisories for SAP NetWeaver relate to remote command execution vulnerabilities, which will be explained later in this post. On the Oracle side, all six advisories relate to cross-site scripting (XSS) attacks on the core business application Oracle E-Business Suite. ResearchPablo Artuso09/21/2016
onapsis.webp 2016-09-13 20:23:25 Missing Authorization Checks – SAP Security Notes September 2016 (lien direct) Today is the second Tuesday of September, which means that SAP has released their monthly batch of Security Notes. SAP published 21 SAP Security Notes this month (6 Notes were published after August the 8th, and did not have any Hot News items. Only four Notes this month were considered to be 'high priority' (16 were Medium and 1 was Low). Two of the four 'high priority' SAP Security Notes are related to the product SAP Adaptive Server Enterprise (SAP ASE - http://go.sap.com/product/data-mgmt/sybase-ase.html):SAP Security NotesEmiliano Fausto09/13/2016
onapsis.webp 2016-09-08 13:34:17 Clickjacking SAP Security Notes: Where to start? (lien direct) IntroductionResearchGaston Traberg09/08/2016
onapsis.webp 2016-08-09 17:36:56 Denial of Service Attacks: SAP Security Notes August 2016 (lien direct) Today, SAP released their latest batch of monthly Security Notes. Despite this month not being specifically critical, Denial of Service attacks are a central point of concern. A Denial of Service (DoS) attack intends to make one or more resource unavailable. In the case of SAP, DoS attacks could be a partial and affect only a specific program or database, or they could be complete, taking all SAP infrastructure offline. SAP Security NotesEmiliano Fausto08/09/2016
onapsis.webp 2016-07-27 19:49:38 Onapsis publishes 12 advisories for Oracle Business Critical Applications (lien direct) Today we have released 12 new Oracle application advisories which affect two different products: Oracle E-Business Suite and JD Edwards. The advisories include various types of vulnerabilities such as Cross Site Scripting, Denial of Service, Password Disclosure and User Creation. After great success uncovering hundreds of vulnerabilities in SAP systems, our Research Labs are expanding our security advisories to now include Oracle products.ResearchMatias Mevied07/28/2016
onapsis.webp 2016-07-21 13:53:43 Onapsis Publishes 15 Advisories for SAP HANA and Building Components (lien direct) Today, Onapsis Research Labs released 15 advisories related to SAP HANA and some building components, as well as Internal Communication Channels (also known as TREXNet). This is the first launch of more than 40 advisories we will be publishing in the following month including several vulnerabilities we have discovered in business critical application such as SAP and Oracle. In this blogpost, we'll analyze two different vulnerabilities affecting SAP HANA.SAP, Security AdvisoriesResearchNahuel D. Sanchez07/21/2016
onapsis.webp 2016-07-20 15:58:37 Oracle Fixes a Record of 276 Vulnerabilities in July 2016 (lien direct) Yesterday, Oracle has released its July 2016 Oracle Critical Patch Update (CPU). This post analyzes it in order to provide Oracle customers with detailed information about the latest vulnerabilities affecting Oracle business critical applications. ResearchMatias Mevied07/20/2016
onapsis.webp 2016-07-12 18:06:01 Understanding Clickjacking Attacks: SAP Security Notes July 2016 (lien direct) On the second Tuesday of every month, SAP releases their latest Security Notes. This month there were 36 SAP Security Notes (taking into account 26 Support Packages and 10 Patch Day Notes & including the ones published after last second Tuesday). Of these notes, there are two important things to highlight: SAP Security NotesEmiliano Fausto07/12/2016
onapsis.webp 2016-07-12 14:29:34 Roadshow Recap: Addressing the SAP Governance Gap (lien direct) Onapsis has just completed its second annual North American Roadshow Series! With stops in the Bay Area, Houston, Chicago, and New York, this initiative was a huge success. During this series, industry professionals and customers from some of the top F1000 organizations collaborated on how to address the growing SAP governance gap within their organizations. As the state of SAP cybersecurity continues to evolve, the SAP governance gap continues to be one of the most common challenges facing organizations across many different industries. CorporateMariano Nunez07/12/2016 ★★★
onapsis.webp 2016-06-16 17:37:25 (Déjà vu) Analyzing SAP Security Notes June 2016 (lien direct) SAP systems run an organization's mission-critical processes, and house an organization's most sensitive data. Because of this, it is critical that these systems receive the proper security they deserve. This security begins with closing the gap of software vulnerabilities by applying security patches released by SAP in a timely manor.SAP Security NotesEmiliano Fausto06/16/2016
onapsis.webp 2016-05-11 12:37:21 DHS US-CERT and Reuters bring SAP cybersecurity into the spotlight (lien direct) Today, based on research performed by our Research Labs, both the U.S. government and business press are discussing the critical topic of SAP business application cybersecurity, bringing it to top of the agenda for CISOs and CIOs worldwide. CorporateMariano Nunez05/11/2016
onapsis.webp 2016-05-10 20:46:35 Analyzing SAP Security Notes May 2016 (lien direct) SAP systems run an organization's mission-critical processes, and house an organization's most sensitive data. Because of this, it is critical that these systems receive the proper security they deserve. This security begins with closing the gap of software vulnerabilities by applying security patches released by SAP in a timely manor.critical vulnerabilities, CVSS, SAP Security NotesSAP Security NotesEmiliano Fausto05/10/2016
onapsis.webp 2016-05-04 18:38:59 2016 North American Roadshow Series - Coming to a City Near You! (lien direct) I'm pleased to announce that today we're kicking off our second annual Onapsis Roadshow series in North America. With all that is going on in the world of SAP cybersecurity, I feel like our roadshows could not have come at a better time. SAP cybersecurity, RoadshowsCorporateMariano Nunez05/04/2016
onapsis.webp 2016-04-25 18:51:57 (Déjà vu) Oracle fixes 136 Software Vulnerabilities in April 2016 (lien direct) As a company, Onapsis is focused on securing business-critical applications such as SAP and Oracle. An important part of our research relies on identifying, and reporting on critical vulnerabilities in Oracle business applications in order to help Oracle customers reduce the risk to their organization.ResearchMatias Mevied04/25/2016
onapsis.webp 2016-04-04 14:40:30 Who is Truly Responsible for Securing SAP Systems? (lien direct) Not too long ago I published a blog which discussed operationalizing your SAP cybersecurity strategy. In that post I discussed the confusion around division of responsibilities, who should own SAP security, and how SAP security gets operationalized within the organization as this is a common problem my team and I have noticed across organizations. SAP, operationalizing SAP cybersecurity, SAP cybersecurity, SAP SecurityCorporateStephen Higgins04/04/2016
onapsis.webp 2016-03-08 20:41:52 (Déjà vu) Analyzing SAP Security Notes March 2016 (lien direct) SAP is a complex and ever changing system, whether because of changes introduced to your SAP implementation to better suit your business or through the application of Security Notes (Patches) to ensure that newly disclosed vulnerabilities are mitigated.SAP, Security Notes, critical vulnerabilities, CVSSSAP Security NotesEmiliano Fausto03/08/2016
onapsis.webp 2016-02-23 21:54:25 Key Takeaways from Ponemon Institute\'s New Study: Uncovering the Risks of SAP Cyber Breaches (lien direct) Today, the Ponemon Institute has released its latest research study titled Uncovering the Risks of SAP Cyber Breaches. As the first independent research study on SAP cybersecurity trends, more than 600 global IT security practitioners were surveyed to uncover perceptions about the threat of an SAP cyber breach and how companies are managing the risk of information theft, modification of data and disruption of business processes. Ponemon, SAP Attacks, SAP Cyber-Security, SAP Cyber-attackCorporateMariano Nunez02/24/2016
onapsis.webp 2016-02-10 19:11:55 (Déjà vu) Analyzing SAP Security Notes February 2016 (lien direct) SAP is a complex and ever changing system, whether because of changes introduced to your SAP implementation to better suit your business or through the application of Security Notes (Patches) to ensure that newly disclosed vulnerabilities are mitigated.SAP, Security Notes, critical vulnerabilities, CVSSSAP Security NotesEmiliano Fausto02/10/2016
onapsis.webp 2016-01-22 18:24:20 Oracle Fixes 248 Software Vulnerabilities in January 2016 (lien direct) As a company, Onapsis is focused on securing business-critical applications such as SAP and Oracle. An important part of our research relies on identifying, and reporting on critical vulnerabilities in Oracle business applications in order to help Oracle customers reduce the risk to their organization.ResearchMatias Mevied01/22/2016
onapsis.webp 2016-01-20 20:25:21 Operationalizing SAP Cybersecurity (lien direct) Business-critical applications running on SAP such as enterprise resource planning (ERP), customer relationship management (CRM), human capital management (HCM), business intelligence (BI) and supply chain management (SCM) house an organization's most valuable data and support mission-critical business processes. As we enter 2016, it's no surprise that these systems have become major targets to nation-state attacks, intellectual property theft, financial fraud and sabotage. operationalizing SAP cybersecurity, Infosec, SAP BASISCorporateStephen Higgins01/20/2016
onapsis.webp 2016-01-12 18:21:10 Analyzing SAP Security Notes January 2016 (lien direct) SAP is a complex and ever changing system, whether because of changes introduced to your SAP implementation to better suit your business or through the application of Security Notes (Patches) to ensure that newly disclosed vulnerabilities are mitigated.SAP, Security Notes, critical vulnerabilities, CVSSSAP Security NotesEmiliano Fausto01/12/2016
Last update at: 2024-04-25 14:11:39
See our sources.
My email:

To see everything: Our RSS (filtrered) Twitter