Podcast: Emerging Security Threats to Your Digital Supply Chain
About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
View Author Profile
Jason Frugé, Vice President of Business Application Cybersecurity at Onapsis, was recently featured on an episode of the Enterprise Security Weekly Podcast, Emerging Security Threats to Your Digital Supply Chain. As the former CISO of Fossil, Jason knows the value behind securing your ERP systems and your most mission-critical applications.
In this episode, Jason discusses how missing patches, misconfigurations, issues with custom code and other vulnerabilities are leaving your most important data and applications unprotected—and what to do about it. Listen below!

About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
View Author Profile
Further Reading
Unmanaged “Vibe Coding” Creates Risks for SAP Clean Core StrategiesÂ
It feels as though vibe coding has sparked a wild-west adoption phase for generative AI in enterprise development. The temptation is obvious: massive productivity leaps achieved just by feeding natural language prompts into LLMs to deploy software at record speeds. Organizations are sprinting to integrate these practices, terrified that lagging behind means losing their competitive…
Onapsis and CrowdStrike Expand Partnership to Secure SAP in the Agentic AI Era
By bridging Onapsis’ deep SAP application-layer domain knowledge and threat research with the power of the CrowdStrike Falcon platform, we are eliminating historical blind spots between enterprise SAP systems and central SOC operations.
Inside the SAP MII Vulnerability Cluster: August 2026 Patch Day
SAP released 28 new Security Notes on August 11, 2026. While monthly vulnerability reporting typically centers on headline CVSS scores, the primary narrative this month is a specific product cluster. Six of the released notes impact a single component: SAP Manufacturing Integration and Intelligence (MII). Onapsis Research Labs uncovered all six vulnerabilities during a single,…
