Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud

DoControl: Secure The SaaS Supply Chain

Truth in IT
07/04/2023
44
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this clip. DoControl covers the anatomy of SaaS supply chain attacks, covering five phases: infiltration, implantation, propagation, activation, and exploitation. Attackers gain access to the software supply chain through various techniques such as phishing, social engineering, or exploiting vulnerabilities. Once inside, they implant malicious code and spread it to other systems or applications to maximize the impact. The attackers then activate the code and exploit vulnerabilities to achieve their objectives, which could include data theft or disrupting system functionality.

SaaS supply chain risks focus on machine identity access and associated credentials, particularly in shadow applications that are unsanctioned by the IT department. These shadow apps may contain vulnerabilities or backdoors that can be exploited for unauthorized access to sensitive data. Compromising credentials and privileges involved in application-to-application interconnectivity is a proven technique used by attackers. Third-party apps often request more privileges than necessary, introducing additional accessibility vectors.

The webinar also highlighted notable breaches from the past year, including Samsung, GitHub, and Toyota. These breaches involved the compromise of credentials and OAuth tokens, allowing attackers to access sensitive data and exploit further infrastructure.

DoControl is a SaaS security platform focused on protecting business-critical SaaS applications. Their platform is built on three foundational tenets: discovery and visibility, monitoring and control, and automated remediation. DoControl aims to secure SaaS applications through automated security workflows, driving operational efficiency and enabling business productivity.
Categories:
  • » Cybersecurity » Backup & Recovery
  • » Cybersecurity
  • » Cybersecurity » Identity & Access Management (IAM)
Channels:
News:
Events:
Tags:
  • docontrol
  • repost
  • security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated

            Video's comments: DoControl: Secure The SaaS Supply Chain

            Upcoming Spotlight Events

            • Jun
              24

              Agentic AI Ransomware: What You Need to Know

              06/24/202501:00 PM ET
              • Jul
                29

                QR Codes Exposed: From Convenience to Cybersecurity Nightmare

                07/29/202501:00 PM ET
                More events

                Upcoming 360 View Events

                • Jun
                  18

                  360View: The Data Resilience Imperative – Securing, Scaling & Optimizing Enterprise Data

                  06/18/202512:00 PM ET
                  • Jul
                    24

                    360View: API Security & the Expanding Attack Surface

                    07/24/202512:00 PM ET
                    • Aug
                      21

                      360View: HCI, Cloud, and Virtualization: What’s Next?

                      08/21/202512:00 PM ET
                      More events

                      Upcoming Industry Events

                      • Jun
                        24

                        Ransomware Revealed: Tactics, Entry Points, and Real-World Lessons

                        06/24/202501:00 PM ET
                        • Jun
                          25

                          Anticipating Evolving Threats: Strategies for Detection, Response, and Resilience

                          06/25/202501:00 PM ET
                          • Jun
                            26

                            Mastering Modern Security with Wallarm's Advanced API Solutions

                            06/26/202501:00 PM ET
                            More events

                            Recent Industry Events

                            • May
                              29

                              Dispelling Misconceptions Surrounding API Security

                              05/29/202501:00 PM ET
                              • May
                                08

                                Strengthening API Security through NIST SP 800-228 Guidelines

                                05/08/202501:00 PM ET
                                • Apr
                                  17

                                  Critical Insights on the Discovery, Disclosure, and Impact of an Android Vulnerability

                                  04/17/202502:40 AM ET
                                  More events
                                  Truth in IT
                                  • Advertise
                                  • About Us
                                  • Terms of Service
                                  • Privacy Policy
                                  • Contact Us
                                  • Be Our Guest
                                  • Preference Management
                                  Desktop version
                                  Standard version