SaaS applications have become a real concern for many businesses. And this is even more important when we consider that GenAI are essentially SaaS applications.
See also: SEC: Requires strengthening security in the SaaS world

Security firm Wing (Wing), a SaaS provider, conducted an analysis of 493 companies using software as a service (SaaS) in the fourth quarter of 2023. Their study reveals how companies are using SaaS today and the variety of threats that arise from its use. This unique analysis provides rare and important insights into the scope of risks associated with SaaS, but also provides practical advice for mitigating them and ensuring that it can be widely used without compromising security.
2023 brought us some famous examples of malicious actors exploiting or directly attacking SaaS, including the North Korean UNC4899 group, the 0ktapus malware group , and the Russian Midnight Blizzard APT group, which attacked well-known organizations like JumpCloud , MGM Resorts, and Microsoft (respectively), as well as many others that often remain unknown.
The first finding from this research validates that these applications are undoubtedly an integral part of the toolkit and vendor set of modern organizations. Even in the most austere companies, when an attentive employee needs a quick and effective solution, they will seek it out and use it to complete their tasks faster and better.
Therefore, any organization concerned with the security of its supply chain should adopt SaaS security measures. According to the MITRE ATT&CK technique titled “Trusted Relationships” (T1199), a supply chain attack occurs when an attacker targets a supplier to exploit it as a means to penetrate a wider network of companies. By trusting external SaaS vendors with sensitive data, organizations expose themselves to supply chain risks that go beyond immediate security concerns.
See also: Welltok: Data breach affects 8.5 million patients
Four common risks for SaaS
1) Shadow SaaS
The first problem with using SaaS is the fact that it often goes completely unnoticed: The number of applications used by organizations is typically 250% greater than what is revealed by a basic and frequently used request in the workplace.
2) MFA Bypassing
Wing's research shows a trend where users are choosing to use a username/password to access the services they need, bypassing the security measures that have been put in place.
3) Forgotten tokens
Users use the tokens they need in applications, which is essential for SaaS applications to perform their purpose. The problem is that these tokens are often forgotten after a few or even one use. Wing’s research revealed a large number of unused tokens over a 3-month period, creating an unnecessarily large attack surface for many customers.
4) The new risk of Shadow AI
At the beginning of 2023, security teams focused primarily on a select few well-known services that offer access to AI-powered models. However, as the year progressed, thousands of conventional SaaS applications adopted AI models. Organizations were forced to agree to updated terms and conditions that allow these applications to use and improve their models using organizations’ most confidential data.
See also: LogicMonitor customers hit by data breach

The report ends on a positive note, outlining ways companies can address the growing risk of the SaaS supply chain.
- Continuous detection and management of unauthorized technological activities (shadow IT).
- Priority in addressing incorrect SaaS configurations.
- Optimize anomaly detection with predefined frameworks, automating where possible.
- Monitor all SaaS applications that use artificial intelligence and check the SaaS for updates to the terms and conditions regarding the use of artificial intelligence.
For the full list of findings, tips for ensuring secure SaaS usage, and a SaaS security forecast for 2024, **download the full report here**.
SaaS solutions are particularly beneficial for the software industry. Software companies can offer their products as services over the internet, eliminating the need for physical installation and maintenance. The retail industry also benefits from SaaS solutions. systems allow for the automation of ordering and inventory processes, as well as customer and sales management.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
IT companies can use SaaS solutions to effectively manage their programs, develop software, and support their customers. The healthcare industry also benefits from SaaS solutions. These systems can help automate patient management processes, organize medical records, and manage healthcare services.
Finally, educational organizations can use SaaS solutions to effectively manage learning management systems, organize educational resources, and deliver distance learning.
Source: thehackernews
