saas security news
2 stories
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor.…

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A cybercrime group, identified as UNC6671, has reportedly launched a series of vishing attacks aimed at employees' personal phones to compromise Software-as-a-Service (SaaS) data. The attacks involve the impersonation of IT support personnel, with the ultimate goal of tricking individuals into divulging credentials and multi-factor authentication (MFA) tokens through fraudulent login portals.