What’s New in Cybersecurity Extension for SAP, Version 5.2?

Version 5.2 of the Cybersecurity Extension for SAP introduces significant enhancements, including comprehensive support for SAP Business Technology Platform (BTP), critical access and Segregation of Duties (SoD) monitoring for SAP ECC, and new alerts for emerging threats. This release expands real-time threat detection and compliance monitoring across modern and legacy SAP environments. The latest update provides robust […]

AI Agents Exploit 87% of Known Vulnerabilities: What This Means for SAP Security

A recent study from the University of Illinois has shown that AI agents, specifically using OpenAI’s GPT-4, can autonomously exploit security vulnerabilities with an 87% success rate when given access to CVE advisories. This groundbreaking research highlights the increasing risk of automated cyberattacks, significantly lowering the cost and complexity for threat actors. For organizations running […]

How to Protect SAP Systems Against Ransomware

SAP systems are not immune to ransomware and can be compromised through vulnerable operating systems, insecure protocols, and exploited trust relationships. In response to recent high-profile breaches at companies like MGM Resorts and Caesars Entertainment, Layer Seven Security has released an updated guide to help organizations prevent, detect, and recover from ransomware attacks within their […]

Cybersecurity Threats to SAP Systems: 5 Key Risks and Recommendations

Managing cybersecurity for SAP systems requires addressing unpatched vulnerabilities, ransomware, credentials compromise, system interfaces, and access controls. This report, based on the 2023 Cybersecurity Threats to SAP Systems Report, outlines actionable strategies to secure your environment using SAP ALM platforms and the Cybersecurity Extension for SAP. Executive Summary The 2023 landscape for SAP security is dominated by […]

Security Advisory: Critical SAP ICMAD Vulnerabilities (CVE-2022-22536)

International threat intelligence agencies, including CISA and CERT-EU, have issued urgent security advisories regarding the ICMAD (Internet Communication Manager Advanced Desync) vulnerabilities. These critical flaws affect the SAP Internet Communication Manager (ICM), a standard component of SAP NetWeaver and the SAP Web Dispatcher, and require immediate patching to prevent full system compromise. What is the […]

Securing SAP Solutions from Log4Shell: A Critical Guide

Log4Shell (CVE-2021-44228) is one of the most significant security vulnerabilities in decades. This zero-day remote code execution (RCE) flaw in the open-source Java logging utility, Log4j, allows unauthenticated attackers to remotely execute arbitrary code, potentially leading to a complete system compromise. Why is Log4Shell a major risk for SAP? Log4j is a widely used logging […]

Securing SAP Systems from Log4J Exploits: A Critical Guide

The Log4Shell vulnerability (CVE-2021-44228) is one of the most serious security threats in recent decades. This remote code execution (RCE) flaw in the Apache Log4j logging framework allows unauthenticated attackers to remotely execute arbitrary code, potentially leading to the complete compromise of affected SAP applications and systems. What is the Log4J vulnerability? Log4j is an […]

CISA Directive: Remediating Actively Exploited SAP Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 22-01, mandating that government departments and agencies remediate specific vulnerabilities known to be actively exploited. This directive highlights six critical SAP vulnerabilities that pose significant risks to information systems, requiring remediation to ensure landscape security. What is the CISA Known Exploited Vulnerabilities (KEV) […]

Protecting SAP Systems from Ransomware Attacks

Recent high-profile incidents, such as the Colonial Pipeline attack, have highlighted the devastating impact of ransomware on critical infrastructure. With ransomware attacks increasing by 300% over the past year, organizations face significant operational risks: the average downtime from an attack is 21 days, while full recovery can take up to 287 days. Why host-level security […]

Cybersecurity Extension for SAP Identifies Signatures of Active SAP Cyberattacks

Recent research confirms that attackers are actively targeting and weaponizing vulnerabilities in SAP applications. With some unprotected cloud installations being compromised in under three hours, and patches being weaponized in less than 72 hours, organizations must move beyond basic patching to implement active threat detection. The Reality of Active SAP Exploitation A joint report by […]