Onapsis

Onapsis Protecting the business-critical applications that power the global economy

Onapsis protects the business-critical applications that power the global economy including ERP, CRM, PLM, HCM, SCM and BI applications from SAP®, Oracle® and leading SaaS providers. Onapsis proudly serves more than 300 of the world’s leading brands including 20% of the Fortune 100 and partners with leading consulting and audit firms such as Accenture, Deloitte, IBM, PwC and Verizon. The Onapsis R

esearch Labs is responsible for the discovery and mitigation of more than 800 zero-day business-critical application vulnerabilities.

17 years of innovation, dedication, and securing what matters most. 🎉✨For nearly two decades, we’ve had the privilege of...
09/01/2026

17 years of innovation, dedication, and securing what matters most. 🎉✨

For nearly two decades, we’ve had the privilege of building cutting-edge solutions and protecting the world’s most critical business applications. 🌎🛡️

A huge thank you to our team, partners, and the 300+ leading global brands who trust us to secure their core operations every single day. Here’s to the next chapter of growth and innovation! 🥂

Moving to the cloud boosts agility, but hybrid environments come with a hidden catch: complex interconnections.Bridging ...
08/31/2026

Moving to the cloud boosts agility, but hybrid environments come with a hidden catch: complex interconnections.

Bridging on-prem and cloud setups broadens your attack surface and gives attackers new entry points.

💡 The takeaway: Innovation without a unified security strategy leaves the door wide open.

How is your team locking down cross-environment attack paths?

Check out how your peers are securing their ERP environments in the age of AI in our latest report: https://bit.ly/4g1VBcZ

Did you catch our live walkthrough earlier this week with the research team?The leading SAP security research team, Onap...
08/28/2026

Did you catch our live walkthrough earlier this week with the research team?

The leading SAP security research team, Onapsis Research Labs, walked attendees through the unintentional expanded attack surface that can occur within SAP applications when moving to the cloud.

Cloud migration drives speed and innovation, but linking cloud and on-premise systems creates complex interconnections. This expands your attack surface and opens new paths for cyber threats.

No worries if you missed it, the session is now on-demand to stream however and whenever you like!

▶️ https://bit.ly/4wPxHXr

Adversaries weaponize SAP vulnerabilities in minutes. Enterprise SOCs can't afford ERP blind spots.That’s why Onapsis an...
08/27/2026

Adversaries weaponize SAP vulnerabilities in minutes.

Enterprise SOCs can't afford ERP blind spots.

That’s why Onapsis and CrowdStrike have deepened our partnership. We’ve integrated Onapsis Assess with CrowdStrike Falcon Exposure Management (FEM) to bring deep SAP intelligence into a single console.

What are the key benefits?
- Complete Visibility: Eliminate the gap between SAP and your SOC.
- Smart Prioritization: Focus on real-world exploitability, not raw volume.
- Rapid Response: Neutralize attack paths before business disruption.

🔗 Learn more in Mariano's latest blog: https://bit.ly/4gED2eg

Plus, if you'are attending Fal.Con 2026, you'll have the chance to join Álvaro Del Hoyo and Mariano Nunez for "Defending SAP Critical Systems in the Frontier AI Era" on Sept 2 @ 12:30 PM PDT.

👉 Add it to your agenda or book a 1:1 with us in Vegas! https://bit.ly/3SijXXb

Heading to SAP for Utilities in San Antonio this October?Stop by Booth  #410 to meet with the Onapsis team! Discover how...
08/27/2026

Heading to SAP for Utilities in San Antonio this October?

Stop by Booth #410 to meet with the Onapsis team! Discover how our SAP-endorsed, premium-certified cybersecurity solutions help utility companies eliminate critical application blindspots, streamline compliance, and build true cyber resilience.

📅 When: October 6–9, 2026
📍 Where: San Antonio Marriott Rivercenter | Booth #410

Ready to secure your mission-critical SAP environment? Request a meeting with our security experts!



https://bit.ly/45Qpyao

08/26/2026

We're going live in one hour! ⏳
(10 a.m. EDT)

Members of Onapsis Research Labs will demonstrate real-world threat activity live. See how leading organizations stay one step ahead, manage the expanded attack surface created by cloud migrations, and prevent threat actors from accessing critical SAP applications.

Bring your questions and get answers from the brightest minds in SAP threat research, backed by over 16 years of hands-on experience protecting SAP landscapes from modern threat actors.

Join us here ➡️ https://bit.ly/46lieUb

Set your reminders, we're going live tomorrow at 10 a.m. EDT! 🔔If you’re migrating SAP to the cloud, you might be leavin...
08/25/2026

Set your reminders, we're going live tomorrow at 10 a.m. EDT! 🔔

If you’re migrating SAP to the cloud, you might be leaving backdoors open without even realizing it.

Join Onapsis offensive security experts as they demonstrate live how threat actors exploit subtle gaps in SAP Cloud Connector, BTP, and RFC Destinations to move laterally through hybrid environments, and the exact steps you need to take to lock them down.

Don't wait until a misconfiguration becomes a breach. Secure your spot before doors close!

👉 https://bit.ly/4h3yobB

Kicking off your week? What better way to do that then with our Defenders Monthly Newsletter. Grab your iced coffee and ...
08/24/2026

Kicking off your week? What better way to do that then with our Defenders Monthly Newsletter. Grab your iced coffee and let's go!

This month's features include:

💻 Hacking & Defending SAP Live - Episode IV. This Wednesday, August 26 at 10 AM EDT our threat research team will outline how threat actors exploit cloud migration misconfigurations and how to mitigate.
⚙️ August's Patch Day Analysis
🔒 Securing the SAP Web Dispatcher
🧼 Clean Core & DevSecOps

👉 Check out August's edition below!

https://bit.ly/3SVXEGV

It's been a busy week for our research team. Let's recap what's been top of mind for Onapsis Research Labs this week.Thi...
08/21/2026

It's been a busy week for our research team. Let's recap what's been top of mind for Onapsis Research Labs this week.

This week's round-up from our Global Threat Intel Network includes:
• Visual Composer: Attack activity targeting Visual Composer is beginning to slow down.
• Legacy Threats: Attackers are still actively probing older vulnerabilities, including CVE-2020-6287 (RECON).
• SAP Commerce Cloud: A new critical warning requires immediate patching to prevent potential exposure.

If you're interested in digging into these insights face-to-face, book a threat briefing with a member of our team today. ⬇️

https://bit.ly/4g9wfck

August's 2026 SAP security round-up is here!As summer wraps up, threat actors aren't slowing down. From critical 10.0 CV...
08/20/2026

August's 2026 SAP security round-up is here!

As summer wraps up, threat actors aren't slowing down. From critical 10.0 CVSS vulnerabilities in SAP Commerce Cloud to lateral movement risks in cloud migrations, staying ahead of SAP threats is essential.

Here’s a quick look at what’s inside our August 2026 Defenders Monthly Newsletter:
💻 Hacking & Defending SAP Live (Ep. IV): Join Pablo Agustin Artuso and Hector Espinoza on August 26 at 10 AM EDT as they demonstrate how threat actors exploit cloud migration misconfigurations and share practical ways to secure your hybrid landscape.
⚙️ August Patch Day Analysis: Breakdown of 33 new/updated patches, featuring a critical HotNews note (CVSS 10.0) and key updates for SAP MII.
🔒 Securing the SAP Web Dispatcher: Why this edge entry point is a primary target for attackers and how to lock down your front door.
🧼 Clean Core & DevSecOps: Onapsis CTO Juan Perez-Etchegoyen breaks down code-level vulnerabilities in SAP BTP extensions and how to automate security in your CI/CD pipeline.

👉 Check out the full issue and subscribe over on LinkedIn!
https://bit.ly/4c3gG4F

Address

Boston, MA

Alerts

Be the first to know and let us send you an email when Onapsis posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Onapsis:

Shortcuts

Share