Threat Dispatches: Actionable SAP Intelligence

2025 was a critical inflection point for SAP cybersecurity. While SAP has always been a prime target for threat actors, the exploitation of CVE-2025-31324, the critical SAP zero day that Mandiant recognized as the most exploited vulnerability in 2025, marked a new, stressful chapter for SAP defenders worldwide. Multiple waves of attack campaigns persisted throughout the year, including a large push jumpstarted by the release of a public exploit for the zero day by ShinyHunters. Moving forward, business-critical SAP applications remain under continuous, targeted attack from sophisticated state-sponsored groups and financially motivated cybercriminals. And the advances in AI have only increased the velocity at which both vulnerabilities and exploits are discovered.
When a critical SAP vulnerability or major attack campaign hits the headlines, your board of directors and C-suite want immediate answers. They need to know if the organization is exposed and what is being done to mitigate the risk. Unfortunately, traditional security feeds and generic IT news are incapable of providing the specific SAP context and insights required to answer those questions quickly and secure the business. Your security and SAP Basis teams are often left scrambling to manually cross-reference whatever threat reports or community updates they can find against your internal SAP asset inventory.
For 17 years, the Onapsis Research Labs have been on the frontlines, defending the SAP global community from critical vulnerabilities and malicious threat actors. As part of their ongoing commitment to arm our clients with high-fidelity, high-impact, actionable threat insights, the Onapsis Research Labs are releasing Threat Dispatches, a weekly intelligence report exclusively delivered through the Threat Intel Center (TIC) within the Onapsis Platform.
These Threat Dispatches ensure your teams are always informed, always prepared, and always ready to act.
What is the Threat Intel Center (TIC)?
The Threat Intel Center (TIC) is the central intelligence hub within the Onapsis Platform. It delivers immediate, one-click access to the latest research, vulnerability analysis, and real-world attack observations straight from the global leaders in SAP threat research.
Instead of forcing your security operations center (SOC) analysts to hunt down fragmented SAP security news, the Threat Intel Center brings the intelligence directly to them. It provides critical threat analysis, exploit warnings, major attack campaign breakdowns, and high-level Patch Tuesday overviews.
Most importantly, the Threat Intel Center automatically correlates this global intelligence with your specific SAP landscape, instantly highlighting which of your assets are affected by a newly disclosed threat.


Inside the Threat Dispatches
Available exclusively to Threat Intel Center subscribers, each Threat Dispatch provides a curated, tactical summary of the active SAP threat landscape.
By synthesizing telemetry and observations from our Global Threat Intelligence Network, current vulnerability research, ongoing monitoring of threat actor groups, and insights from our incident response engagements, the Threat Dispatch delivers deep, focused qualitative analysis of what threat actors are doing right now and where.
Every dispatch equips your team with:
- Active Campaign Breakdowns: Detailed tracking of global attack campaigns, broken down by geography, targeted industry, and threat actor group.
- Exploited CVE Trends: Live delta analysis showing which vulnerabilities (like CVE-2025-31324 or older flaws like RECON) are surging in popularity and which campaigns are cooling down.
- Top Targeted Endpoints: Clear visibility into the specific SAP endpoints and protocols currently under the heaviest reconnaissance and exploitation attempts.
- Indicators of Compromise (IoCs): Weekly updates of new IoCs that emerged through the Onapsis Research Labs ongoing work
- Actionable Remediation Guidance: Direct recommendations on how to deploy compensating controls or prioritize patching efforts to close your most critical exposures.
Backed by 17+ Years of SAP Security Expertise
You won’t find content like these weekly Threat Dispatches anywhere else. Only the Onapsis Research Labs, the most trusted and recognized SAP threat research group in the world, can deliver this type of analysis and threat insights to SAP defenders.
With over 17+ years of specialized experience and more than 1,000 zero-day vulnerability discoveries, Onapsis possesses a depth of knowledge into business-critical security that other security vendors simply cannot match. Our intelligence is regularly cited by global government agencies (including US CISA and Germany’s BSI) and top incident response firms with whom we frequently partner.
By subscribing to the Threat Intel Center, you are directly integrating that world-class expertise into your own security operations.


Arm Your Defenders with Actionable Intelligence
Do not let your SAP landscape remain a blind spot. Equip your security and IT teams with the specialized threat intelligence they need to stay ahead of sophisticated cybercriminals.
