Read full story:Under the shared responsibility model, the part that's left to the business consuming a SaaS service is mostly constrained to how they manage identities — the vehicle by which the app is accessed and used by the workforce. It's no surprise that this has become the soft underbelly in the crosshairs of attackers.
We've seen this time and again in the biggest breaches of recent years, with the highlights including the massive Snowflake campaign in 2024 and the 2025 crime wave attributed to Scattered Spider.
These attacks are so successful because while attackers have moved with the changes to enterprise IT, security hasn't really kept up.
How the Browser Became the Main Cyber Battleground
Browser-based identity attacks surge in 2025, targeting SaaS apps and weak credentials across enterprise accounts.
thehackernews.com
