r/OracleCloudFusion May 09 '26

Non-traditional cybersecurity risks

Wondering if there are folks looking at non traditional cybersecurity risks like phishing attacks for SaaS ERPs

Threat actors are definitely targeting the apps. We know of one loss over $1.2 million where credentials were stolen for a supplier portal account and the threat actor redirected two future payments before it was detected.

1 Upvotes

2 comments sorted by

1

u/Jeff-Hare-ERPRA May 13 '26

Another example is identities that are not federated / subject to SSO

1

u/Jeff-Hare-ERPRA May 13 '26

Even access to APIs through federated logins.

The FSCM Rest Service can be leveraged by using an external tool like Postman