TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bishop Fox

State of the SaaS Security Union

2025-09-16 · Read original ↗

ATT&CK techniques detected

3 predictions
T1525Implant Internal Image
84%
"objects to which salesloft never needed access, enabled solely by poor integration account configurations. - avoid overprivileged accounts provision each user and integration with only the access required for their specific purpose. no shared integration profiles. - restrict acce…"
T1525Implant Internal Image
70%
"my opinion. the campaign has since expanded to google workspace and other integrations. the security gaps exposed the gap in sophistication between these two threat actors is substantial. in just two months, we ’ ve gone from basic phishing attacks to an adversary with a deep und…"
T1525Implant Internal Image
36%
"state of the saas security union we are now facing two concurrent threat actors actively targeting saas applications and their customers : the first group, unc6040 ( also known as shinyhunters or scattered spider ), claims overlap with the actors behind the snowflake breach. they…"

Summary

Two threat groups are exploiting SaaS at scale: one with phishing and data theft, the other with nation-state level tactics exploiting integrations and credentials. Here’s what you need to know and how to protect against the next wave.