The Global Threat Intelligence Network for SAP

When an SAP system is exposed to the Internet without proper security controls, the Onapsis Research Labs have consistently observed how global threat actors will discover and compromise it in three hours or less.

Standard network threat feeds and generalized IP blocklists only take you so far and aren’t sufficient to directly protect your SAP applications from attacks. These tools lack the specialized context required to identify application-layer probes, proprietary transport protocols, and SAP-specific exploits. To defend business-critical applications against global cybercriminal groups and state-sponsored attackers, your security operations center (SOC) requires high-fidelity, real-time threat telemetry from the experts.

The Onapsis Research Labs operates the Global Threat Intelligence Network (GTIN) for SAP, the industry’s largest global telemetry network dedicated exclusively to observing and tracking cyber threats against SAP business-critical applications.

The Current SAP Threat Reality

≤ 3 Hours

Rapid Compromise

The time it takes for attackers to discover and compromise an unprotected, Internet-facing SAP cloud application.

< 72 Hours

Compressed Weaponization

The average window for adversaries to reverse-engineer and exploit newly released SAP security patches.

490% Increase

Dark Web Escalation

The surge in dark web criminal conversations focused exclusively on weaponizing and monetizing SAP exploits.

How the Global Threat Intelligence Network Works

The GTIN is a powerful distributed array of sophisticated threat sensors deployed globally to monitor live, cross-industry SAP enterprise environments. These sensors actively analyze protocols and components like SAP GUI, RFC Gateway, Message Server, HANA, and SAP Fiori that are attractive to threat actors in order to better analyze threat actor activity worldwide.

With the GTIN, Onapsis researchers capture the exact tactics, techniques, and procedures (TTPs) used by global threat actors to target SAP systems. The GTIN logs real-time reconnaissance activity, brute-force attempts, supply chain tampering, and active zero-day exploit campaigns.

Recent live telemetry from the GTIN demonstrates that SAP applications are under sustained, continuous attack:

  • Persistent Targeting of Legacy Flaws: Legacy vulnerabilities like RECON (CVE-2020-6287) are still probed relentlessly every single week.
  • Continuous Attacker IP Rotation: Threat actors rotate their IP addresses wholesale week-to-week, ensuring that static IP blocklists are rendered useless within days.
  • Rapid Weaponization of Zero-Days: High-severity vulnerabilities like the SAP NetWeaver Visual Composer RCE (CVE-2025-31324) escalate from initial public disclosure to multi-actor webshell campaigns within hours.
Security professionals collaborating on threat intelligence

Translating Global Intelligence into Real-Time SAP Defense

Raw data is useless to an enterprise security team without immediate, actionable context. The Onapsis Global Threat Intelligence Network is not just a handful of systems used as a research project. It is a massive system of business-critical applications that acts as a key telemetry engine for the Onapsis Research Labs, ultimately leading to the most advanced capabilities that power the entire Onapsis Platform and protect enterprise customers worldwide.

The insights are instantly productized and delivered directly to your Onapsis products:

1.

Onapsis Threat Intel Center (TIC)

GTIN telemetry feeds directly into the Onapsis Threat Intel Center, providing your teams with real-time reporting on critical vulnerabilities, active exploitation campaigns, and detailed threat actor tracking. Every week, the Onapsis Research Labs deliver key observations and indicators of compromise for your SAP security and your InfoSec teams to utilize to protect your critical SAP landscapes. TIC gives you an immediate, high fidelity read on your exposure by cross-referencing active global campaigns directly with your internal asset inventory.

2.

Pre-Patch Protection in Onapsis Defend

When the GTIN captures an undocumented exploit or zero-day attack vector, Onapsis Research Labs work with Onapsis Product Research teams to implement proprietary exploit and zero-day threat rules into Onapsis Defend. This provides immediate, real-time protection for your SAP systems, keeping them protected for months at a time in advance of the release of official vendor patches from SAP.

3.

Continuous Updates for Assess and Control

Further observations from the GTIN also inform the creation of new security checks, test cases, and configuration rules across Onapsis Assess and Onapsis Control. This ensures your exposure management capabilities and DevSecOps pipelines are continuously updated with content that identifies the latest attack vectors (and, in the case of Control, before insecure, vulnerable code reaches your production systems).

Threat analyst monitoring cyber adversary activity

Tracking the Most Dangerous Cyber Adversaries

Through the Global Threat Intelligence Network, Onapsis has identified and continues to track a growing number of sophisticated threat actors actively leveraging SAP technology as part of their attack campaigns. Attackers are utilizing SAP systems to deploy ransomware, exfiltrate financial statements, and execute massive financial fraud over extended periods (such as FIN13’s $30 million fraud campaign leveraging CVE-2010-5326).

Our researchers actively monitor and analyze TTPs from known advanced persistent threat (APT) groups, financially motivated cybercriminals, and ransomware operations, including:

  • State-Sponsored and APT Groups: APT10, Gelsemium, Earth Lamia, Storm-2460, UNC5221, UNC5174.
  • Financially Motivated Actors: FIN7, FIN13, Scattered Spider, ShinyHunters, LAPSUS$.
  • Ransomware Gangs: Qilin, Cobalt Spider, BianLian, Chaya_004.

Neutralizing AI-Driven Attack Campaigns

The threat landscape has experienced a severe escalation with the introduction of autonomous, AI-driven exploitation. Frontier and off-the-shelf AI models are being utilized by threat actors of all levels of sophistication to scan SAP environments, identify misconfigurations or unpatched vulnerabilities, execute relentless automated brute-force attacks, pull public proof-of-concept exploits, and autonomously execute remote code attacks in minutes.

Similarly, supply chain attacks targeting cloud extensions have become highly sophisticated. In April 2026, Onapsis tracked the “Shai-Hulud” worm variant, which infiltrated official SAP npm packages for SAP Cloud Application Programming (CAP) and Cloud MTA development. The worm stole cloud credentials and spread rapidly across developer workstations and CI/CD pipelines.

To defend against AI-empowered adversaries, high-fidelity threat insights and the capabilities to allow for machine-speed SAP defense are a must. Only Onapsis provides the specialized intelligence and the agentic capabilities required to detect these machine-speed attacks and secure your RISE with SAP transformations against sophisticated supply chain tampering.

Proven Authority in SAP Threat Research

The Onapsis Research Labs is the most trusted and recognized SAP threat research group in the world. Our deep cybersecurity expertise and continuous monitoring capabilities make us the primary intelligence partner for leading global enterprises and federal security agencies.

Zero-Day Disclosures

Our researchers have discovered and safely disclosed over 1,000 zero-day vulnerabilities in enterprise applications.

of Critical SAP Vulnerabilities

In 2025 alone, Onapsis discovered 55% of all critical HotNews (CVSS 9.0-10.0) vulnerabilities within the SAP ecosystem.

US CISA Critical Alerts

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued 6 critical national alerts based directly on Onapsis research.

Threat Knowledgebase

Our intelligence engine indexes over 10,000 application-layer vulnerabilities, attack behaviors, and TTPs.

Our ongoing commitment to responsible disclosure and trusted research is officially recognized in the SAP Security Researcher Acknowledgments, where we significantly outpace the output of every other security researcher recognized.

Eliminate Your SAP Cybersecurity Blind Spot

Stay ahead of advanced persistent threats and zero-day exploit campaigns with the industry’s premier threat intelligence network.