<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Saas-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/saas-security/</link><description>Recent content in Saas-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 11:41:42 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/saas-security/index.xml" rel="self" type="application/rss+xml"/><item><title>UNC6671 Vishing Campaign Targets SaaS Credentials at Financial Firms</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-unc6671-vishing-attacks-target-personal-phones-to-steal-saas/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-unc6671-vishing-attacks-target-personal-phones-to-steal-saas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> UNC6671 exploits human trust rather than software vulnerabilities, so there is no patch or config fix. The campaign reinforces the value of phishing-resistant (FIDO2) MFA on SaaS to limit what a tricked employee can surrender.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Named actor with defined TTPs (IT help-desk impersonation via personal phone → SaaS credential handover) but no IOCs published yet; build or tune detections for anomalous SaaS logins and new device enrollments, and consider hunting for suspicious authentication spikes in M365 or Google Workspace logs correlated with help-desk ticket activity.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> An active data extortion group is deliberately targeting employees at financial services, private equity, and professional services firms by phone; if your org is in those sectors, brief employees this week on the IT impersonation lure and verify that help-desk identity-verification procedures are documented and enforced.&lt;/li>
&lt;/ul></description></item><item><title>ShinyHunters targets SaaS via OAuth abuse, vishing, and guest-access misconfig</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-defending-saas-based-applications-against-shinyhunters-oauth/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-defending-saas-based-applications-against-shinyhunters-oauth/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> ShinyHunters&amp;rsquo; TTPs — OAuth app abuse and misconfigured guest access — directly affect cloud/SaaS configurations engineers own; no KEV or exploitation signals, but audit third-party OAuth app consent grants and tighten guest-access policies in your M365/IdP tenant this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft Threat Intelligence documents an active, named campaign; review the blog for IOCs and ATT&amp;amp;CK-mappable TTPs, then hunt for anomalous OAuth token grants and vishing-preceded MFA/auth events in identity logs since the publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> ShinyHunters&amp;rsquo; supply-chain and OAuth abuse pattern against SaaS platforms warrants a SaaS vendor review this quarter — confirm key vendors enforce OAuth app allowlisting and have disabled unnecessary guest access — no specific named-vendor breach requiring immediate stakeholder communication.&lt;/li>
&lt;/ul></description></item></channel></rss>