ASOS Breach Reveals the Risks in Customer-Facing SaaS
The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.
Excerpt from the primary source: Dark Reading
Who is affected
Security professionals
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
tenfold CE: Our free Identity Governance tool just got 2 new features
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity.
Beyond source code: A path to the keys to the kingdom
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure.
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.
SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)
