Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SAP Patch Tuesday: August Security Updates & Breach Insights

Onapsis
05/08/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • SAP's August Patch Tuesday includes 25 security notes with two critical hot news items: a CVSS 9.8 Business Objects vulnerability requiring immediate patching and a CVSS 9.1 Node.js vulnerability affecting SAP Build Apps that requires rebuilding and redeploying applications.
  • The National Public Data breach exposed social security numbers and personal information of millions, now freely available after initially being sold for $3.5 million, highlighting the need for proactive credit monitoring and digital identity protection measures.
  • A zero-day browser vulnerability affecting Safari, Chrome, and Firefox allows attackers to bypass protections via 0.0.0.0 requests, emphasizing the critical importance of keeping browsers updated as JavaScript disabling is not practical for modern web use.
  • SAP's continued growth with 28% cloud backlog increase and 25% cloud revenue growth demonstrates the expanding attack surface of critical business applications that power essential infrastructure across multiple industries.
  • Onapsis Research Labs contributed to nearly 25% of the vulnerabilities fixed in SAP's August release, showcasing their significant role in identifying and reporting security issues in the SAP ecosystem.

August SAP Security Updates and Critical Vulnerabilities

This episode covers SAP's August Patch Tuesday release, which includes 25 new and updated security notes addressing vulnerabilities across the SAP technology stack. Two hot news items stand out: a critical SAP Business Objects vulnerability (CVE with CVSS 9.8) that allows full system compromise, and a Node.js library vulnerability (CVSS 9.1) affecting SAP Build Apps deployments. Organizations running these technologies need immediate patching and, in the case of Build Apps, must rebuild and redeploy applications with updated Node.js versions. Notably, Onapsis Research Labs contributed to nearly 25% of the vulnerabilities fixed in this release, demonstrating their deep expertise in SAP security research.

National Public Data Breach and Digital Identity Protection

The discussion addresses a significant data breach at National Public Data, a background check provider, which exposed social security numbers, names, addresses, and other personal information. Initially offered for sale at $3.5 million, the data is now freely available. This breach highlights the broader challenge of data security across third-party vendors that consumers have no direct relationship with but whose services are used by employers and other organizations. The episode emphasizes the importance of defensive measures including credit monitoring, fraud alerts, IRS identity protection, and maintaining awareness of one's digital footprint across the interconnected digital ecosystem.

Browser Zero-Day and SAP's Continued Market Growth

The episode covers a zero-day vulnerability discovered by Oligo Security affecting major browsers (Safari, Chrome, Firefox) that allows attackers to bypass protections by sending requests to 0.0.0.0, potentially gaining unauthorized access to local resources. The primary mitigation is keeping browsers updated, as disabling JavaScript is impractical for modern web browsing. Additionally, SAP's latest quarterly results show significant growth with cloud backlog up 28%, cloud revenue up 25%, and overall customer revenue up 10%, indicating the expanding attack surface of SAP applications and reinforcing the critical importance of securing these systems that power essential infrastructure across energy, food, healthcare, and other vital sectors.

Chapters

0:00 - Introduction and Welcome
1:23 - SAP August Patch Tuesday Overview
2:20 - Critical Business Objects Vulnerability
3:04 - Node.js Vulnerability in SAP Build Apps
4:24 - National Public Data Breach Discussion
8:35 - Browser Zero-Day Vulnerability
10:28 - SAP Financial Results and Growth
13:10 - Upcoming C2 Botnet Webinar

Key Quotes

1:52 "Almost 25% of the nodes that were released by SAP fixing security vulnerabilities were fixing vulnerabilities reported by the Onapsis Research Labs."
2:32 "This is a vulnerability affecting SAP business objects. There was a lot of media attention from this vulnerability because of the high CVSS and the criticality because an attacker can fully compromise the system in impacting confidentiality, integrity and availability."
7:40 "We are one big system in this digital space, right? One impact somewhere can have an impact on us elsewhere."
11:03 "They operate depending on SAP up and running, and most of them would not be able to operate if those systems are down."
11:34 "The cloud backlog went up 28% on the last quarter. Cloud revenue up 25%. Customer revenue up 10% considering everything cloud and on cloud."

Categories:
  • » Cybersecurity » Data Security
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Data Privacy
  • Vulnerability Management
  • Threat Intelligence
  • Technical Deep Dive
  • SAP Security Patches
  • Patch Tuesday
  • Business Objects Vulnerabilities
  • Node.js Security
  • Data Breaches
  • Social Security Number Theft
  • Browser Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SAP Patch Tuesday: August Security Updates & Breach Insights

              Upcoming Webinar Calendar

              • 05/12/2026
                01:00 PM
                05/12/2026
                Transforming Black Box to Glass Box: Revealing Hidden Threats and AI Risks through Data Lineage
                https://www.truthinit.com/index.php/channel/1895/transforming-black-box-to-glass-box-revealing-hidden-threats-and-ai-risks-through-data-lineage/
              • 05/12/2026
                11:30 PM
                05/12/2026
                Implementing Effective Strategies for Active Directory Security and Data Protection
                https://www.truthinit.com/index.php/channel/1888/implementing-effective-strategies-for-active-directory-security-and-data-protection/
              • 05/13/2026
                01:00 AM
                05/13/2026
                Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1890/transforming-the-black-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/13/2026
                05:00 AM
                05/13/2026
                Transforming Black Box to Glass Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1894/transforming-black-box-to-glass-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/19/2026
                01:00 PM
                05/19/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle
                https://www.truthinit.com/index.php/channel/1936/establishing-a-robust-ai-governance-framework-for-genai-throughout-its-lifecycle/
              • 05/20/2026
                10:00 PM
                05/20/2026
                APAC: Establishing an AI Governance Framework for GenAI Throughout the Deployment Process
                https://www.truthinit.com/index.php/channel/1953/establishing-an-ai-governance-framework-for-genai-throughout-the-deployment-process/
              • 05/21/2026
                11:00 AM
                05/21/2026
                The Autonomous Era: Orchestrating a Resilient Enterprise
                https://www.truthinit.com/index.php/channel/1372/the-autonomous-era-orchestrating-a-resilient-enterprise/
              • 05/27/2026
                04:00 AM
                05/27/2026
                Rivoluziona i rischi dell'AI in opportunità con Netskope AI Security
                https://www.truthinit.com/index.php/channel/1925/rivoluziona-i-rischi-dellai-in-opportunità-con-netskope-ai-security/
              • 05/28/2026
                10:00 AM
                05/28/2026
                Harnessing AI: Transforming Perception into Purposeful Mastery
                https://www.truthinit.com/index.php/channel/1924/harnessing-ai-transforming-perception-into-purposeful-mastery/
              • 05/28/2026
                01:00 PM
                05/28/2026
                AI in the Fast Lane: Effectively Managing AI Security for Small Teams
                https://www.truthinit.com/index.php/channel/1951/ai-in-the-fast-lane-effectively-managing-ai-security-for-small-teams/
              • 06/02/2026
                01:00 PM
                06/02/2026
                Satori Spring: Insights from Recent Research on the 2026 Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/satori-spring-insights-from-recent-research-on-the-2026-threat-landscape/
              • 06/04/2026
                02:00 AM
                06/04/2026
                Mastering the Unseen: Managing Shadow AI and Agentic MCP Traffic
                https://www.truthinit.com/index.php/channel/1948/mastering-the-unseen-managing-shadow-ai-and-agentic-mcp-traffic/
              • 06/16/2026
                07:00 AM
                06/16/2026
                Transforming Data Risk into Actionable Priorities: What to Address First
                https://www.truthinit.com/index.php/channel/1952/transforming-data-risk-into-actionable-priorities-what-to-address-first/

              Upcoming Events

              • May
                12

                Transforming Black Box to Glass Box: Revealing Hidden Threats and AI Risks through Data Lineage

                05/12/202601:00 PM ET
                • May
                  12

                  Implementing Effective Strategies for Active Directory Security and Data Protection

                  05/12/202611:30 PM ET
                  • May
                    13

                    Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage

                    05/13/202601:00 AM ET
                    • May
                      13

                      Transforming Black Box to Glass Box: Revealing AI Risks and Hidden Threats through Data Lineage

                      05/13/202605:00 AM ET
                      • May
                        19

                        Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle

                        05/19/202601:00 PM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version