Mini Shai-Hulud: Understanding the SAP Supply Chain Malware

Mini Shai-Hulud is a malware campaign that targeted the software supply chain for SAP cloud development by injecting malicious code into specific npm packages. Active for a few hours on April 29, 2026, the attack was designed to steal sensitive credentials, including GitHub tokens, npm tokens, and cloud credentials from developers using these tools. This […]

How to Protect SAP Systems from SQL Injection Attacks Highlighted by FBI & CISA

The FBI and CISA have issued an urgent alert regarding the active exploitation of SQL injection vulnerabilities by cybercrime groups like CL0P (TA505). These attacks have resulted in significant ransomware extortion, underscoring the critical need for organizations to secure their software—especially custom applications running on platforms like SAP. This post breaks down the recent FBI […]

How to Secure Custom SAPUI5 Applications Using the Cybersecurity Extension for SAP

Custom SAPUI5 applications are a core component of modern SAP environments, but they lack the native security patching provided by SAP, making them prime targets for attackers. To secure these applications, organizations must implement automated static source code scanning to identify and remediate vulnerabilities throughout the development lifecycle. Why is custom SAPUI5 application security critical? […]