SAN FRANCISCO, California: Cybersecurity firm Obsidian Security is raising alarms about escalating security risks from unauthorized SaaS-to-SaaS application integrations, warning enterprises face massive breach exposure without continuous visibility across their software ecosystems.
Joseph Gothelf, Wyndham’s Vice President of Cybersecurity, stated, “In the absence of continuous visibility into the entire SaaS ecosystem, especially unauthorized activity between SaaS applications, we are looking at a huge data breach waiting to happen.”
The warning comes as Obsidian Security demonstrated its ability to detect the recent Salesloft breach in near real-time. Company CEO Hasan Imam stated Obsidian detected breach signs “earlier than anybody else,” operating in parallel with incident response firm Mandiant, adding “None of our customers lost any data due to this breach.”
The security challenge stems from the proliferation of SaaS application integrations that operate outside traditional security perimeters. Imam emphasized, “SaaS-to-SaaS security requires a new layer in enterprise defense and focused investment,” noting it is “architecturally separated from all the things we have been thinking about,” including endpoint protection, network security, and user access controls.
Traditional enterprise security architectures fail to address unauthorized data flows between connected SaaS applications, creating blind spots that attackers increasingly exploit. Imam stated the threat “requires a novel approach and focus to truly solve this problem,” as conventional security tools lack visibility into application-to-application communications.
The Salesloft breach highlighted how SaaS integrations can serve as attack vectors, with compromised applications potentially accessing data across entire connected ecosystems. Enterprises typically deploy dozens or hundreds of SaaS applications with complex integration patterns, creating extensive attack surfaces.
Obsidian Security’s platform provides continuous monitoring of SaaS application behavior, detecting anomalous integration activity and unauthorized data access patterns. The company’s early detection capability during the Salesloft incident demonstrates how real-time SaaS security monitoring can prevent data exfiltration even when breaches occur upstream.
California: Google has recently announced new features, namely “switching tools”, to help people make a switch from other AI chatbots, such as ChatGPT…
California: WhatsApp is introducing a slew of new features for its users, all aimed at making chats easier to manage and faster to respond to…
San Diego: Shield AI has raised $2 billion in new funding at a $12.7 billion…
Tel Aviv: Conntour has raised $7 million in seed funding to build an AI-powered search…
San Francisco: Deccan AI has raised $25 million in a Series A round to scale…
California: Google has officially launched Lyria 3 Pro, a new artificial intelligence model designed to generate…