The Global Threat Intelligence Network for SAP

When an SAP system is exposed to the Internet without proper security controls, the Onapsis Research Labs have consistently observed how global threat actors will discover and compromise it in three hours or less.
Standard network threat feeds and generalized IP blocklists only take you so far and aren’t sufficient to directly protect your SAP applications from attacks. These tools lack the specialized context required to identify application-layer probes, proprietary transport protocols, and SAP-specific exploits. To defend business-critical applications against global cybercriminal groups and state-sponsored attackers, your security operations center (SOC) requires high-fidelity, real-time threat telemetry from the experts.
The Onapsis Research Labs operates the Global Threat Intelligence Network (GTIN) for SAP, the industry’s largest global telemetry network dedicated exclusively to observing and tracking cyber threats against SAP business-critical applications.
How the Global Threat Intelligence Network Works
The GTIN is a powerful distributed array of sophisticated threat sensors deployed globally to monitor live, cross-industry SAP enterprise environments. These sensors actively analyze protocols and components like SAP GUI, RFC Gateway, Message Server, HANA, and SAP Fiori that are attractive to threat actors in order to better analyze threat actor activity worldwide.
With the GTIN, Onapsis researchers capture the exact tactics, techniques, and procedures (TTPs) used by global threat actors to target SAP systems. The GTIN logs real-time reconnaissance activity, brute-force attempts, supply chain tampering, and active zero-day exploit campaigns.
Recent live telemetry from the GTIN demonstrates that SAP applications are under sustained, continuous attack:
- Persistent Targeting of Legacy Flaws: Legacy vulnerabilities like RECON (CVE-2020-6287) are still probed relentlessly every single week.
- Continuous Attacker IP Rotation: Threat actors rotate their IP addresses wholesale week-to-week, ensuring that static IP blocklists are rendered useless within days.
- Rapid Weaponization of Zero-Days: High-severity vulnerabilities like the SAP NetWeaver Visual Composer RCE (CVE-2025-31324) escalate from initial public disclosure to multi-actor webshell campaigns within hours.


Tracking the Most Dangerous Cyber Adversaries
Through the Global Threat Intelligence Network, Onapsis has identified and continues to track a growing number of sophisticated threat actors actively leveraging SAP technology as part of their attack campaigns. Attackers are utilizing SAP systems to deploy ransomware, exfiltrate financial statements, and execute massive financial fraud over extended periods (such as FIN13’s $30 million fraud campaign leveraging CVE-2010-5326).
Our researchers actively monitor and analyze TTPs from known advanced persistent threat (APT) groups, financially motivated cybercriminals, and ransomware operations, including:
- State-Sponsored and APT Groups: APT10, Gelsemium, Earth Lamia, Storm-2460, UNC5221, UNC5174.
- Financially Motivated Actors: FIN7, FIN13, Scattered Spider, ShinyHunters, LAPSUS$.
- Ransomware Gangs: Qilin, Cobalt Spider, BianLian, Chaya_004.
Neutralizing AI-Driven Attack Campaigns
The threat landscape has experienced a severe escalation with the introduction of autonomous, AI-driven exploitation. Frontier and off-the-shelf AI models are being utilized by threat actors of all levels of sophistication to scan SAP environments, identify misconfigurations or unpatched vulnerabilities, execute relentless automated brute-force attacks, pull public proof-of-concept exploits, and autonomously execute remote code attacks in minutes.
Similarly, supply chain attacks targeting cloud extensions have become highly sophisticated. In April 2026, Onapsis tracked the “Shai-Hulud” worm variant, which infiltrated official SAP npm packages for SAP Cloud Application Programming (CAP) and Cloud MTA development. The worm stole cloud credentials and spread rapidly across developer workstations and CI/CD pipelines.
To defend against AI-empowered adversaries, high-fidelity threat insights and the capabilities to allow for machine-speed SAP defense are a must. Only Onapsis provides the specialized intelligence and the agentic capabilities required to detect these machine-speed attacks and secure your RISE with SAP transformations against sophisticated supply chain tampering.

Proven Authority in SAP Threat Research
The Onapsis Research Labs is the most trusted and recognized SAP threat research group in the world. Our deep cybersecurity expertise and continuous monitoring capabilities make us the primary intelligence partner for leading global enterprises and federal security agencies.
Our researchers have discovered and safely disclosed over 1,000 zero-day vulnerabilities in enterprise applications.
In 2025 alone, Onapsis discovered 55% of all critical HotNews (CVSS 9.0-10.0) vulnerabilities within the SAP ecosystem.
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued 6 critical national alerts based directly on Onapsis research.
Our intelligence engine indexes over 10,000 application-layer vulnerabilities, attack behaviors, and TTPs.
Our ongoing commitment to responsible disclosure and trusted research is officially recognized in the SAP Security Researcher Acknowledgments, where we significantly outpace the output of every other security researcher recognized.

Eliminate Your SAP Cybersecurity Blind Spot
Stay ahead of advanced persistent threats and zero-day exploit campaigns with the industry’s premier threat intelligence network.
