SAP

  • Blog

    Capgemini and SAP are teaming up with Mistral – here’s why

    Capgemini has joined forces with SAP and Mistral AI to develop custom AI tools for sensitive industries, including finance, defense, utilities, and public sector. The rise of AI has raised concerns about the risks, in particular with regards to data security in sensitive industries such as the public sector — with a majority of security leaders worried that AI could…

    Read More »
  • Blog

    Ransomware gangs join ongoing SAP NetWeaver attacks

    Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers. SAP released emergency patches on April 24 to address this NetWeaver Visual Composer unauthenticated file upload security flaw (CVE-2025-31324), days after it was first tagged by cybersecurity company ReliaQuest as targeted in the wild.  Successful exploitation…

    Read More »
  • Blog

    SAP patches second zero-day flaw exploited in recent attacks

    SAP has released patches to address a second vulnerability exploited in recent attacks targeting SAP NetWeaver servers as a zero-day. The company issued security updates for this security flaw (CVE-2025-42999) on Monday, May 12, saying it was discovered while investigating zero-day attacks involving another unauthenticated file upload flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer that was fixed in…

    Read More »
  • Blog

    Chinese hackers behind attacks targeting SAP NetWeaver servers

    Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor. SAP released an out-of-band emergency patch on April 24 to address this unauthenticated file upload security flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer, days after cybersecurity company ReliaQuest first detected the vulnerability being targeted in…

    Read More »
  • Blog

    Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw

    Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers. SAP NetWeaver is an application server and development platform that runs and connects SAP and non-SAP applications across different technologies. Last week, SAP disclosed an unauthenticated file upload vulnerability, tracked as CVE-2025-31324, in SAP NetWeaver Visual Composer,…

    Read More »
  • Blog

    SAP fixes suspected Netweaver zero-day exploited in attacks

    SAP has released out-of-band emergency NetWeaver updates to fix a suspected remote code execution (RCE) zero-day flaw actively exploited to hijack servers. The vulnerability, tracked under CVE-2025-31324 and rated critical (CVSS v3 score: 10.0), is an unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer, specifically the Metadata Uploader component. It allows attackers to upload malicious executable files without needing…

    Read More »
  • Blog

    SAP rolls out ‘Joule for Developers’ AI coding assistant

    SAP has announced ‘Joule for Developers’, its new an AI coding tool for programmers and developers aimed at driving staff efficiencies and freeing up time for tasks that AI cannot complete. The capabilities will be available in the SAP Business Suite, more specifically SAP Build Process Automation and SAP Buil Apps. Joule for Developers will bolster previously announced capabilities in…

    Read More »
  • Blog

    SAP fixes critical vulnerabilities in NetWeaver application servers

    SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information. As part of the January Security Patch Day, the vendor also released updates for other products to patch 12 additional issues rated with medium and high severity. “SAP strongly recommends that the customer visits the Support Portal and applies…

    Read More »
  • Blog

    SAP launches sovereign cloud service for UK customers

    SAP has announced new sovereign cloud capabilities in the UK, meaning customers will now be able to process data entirely within the borders of the country. The offering is now fully operational and available to customers, SAP said in a statement, and is designed to meet the highest standards of data residency, security, and compliance within the UK. It’s targeted…

    Read More »
  • Blog

    UiPath and SAP team up to streamline cloud migrations

    UiPath and SAP have unveiled a new integration designed to help SAP customers boost their automation capabilities and streamline cloud migrations. Slated for release this month, the enterprise automation specialist’s UiPath Platform is being integrated with SAP Build Process Automation and delivered as a new SAP Solution Extension. The offering has been designed to facilitate the automation of business processes…

    Read More »
Back to top button
close