Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
βοΈ Free SaaS Risk Assessment Platforms No One Talks About βοΈ
SaaS adoption is skyrocketing, but unchecked apps create hidden security and compliance risks. Luckily, there are free platforms CISOs can leverage to assess SaaS risk without a huge budget.
Here are top free SaaS risk assessment tools:
1οΈβ£ BitSight Free Insights β Basic SaaS risk scoring and vendor exposure overview.
π https://www.bitsight.com/
2οΈβ£ Cloud Security Alliance (CSA) STAR Self-Assessment β Framework to evaluate cloud/SaaS provider security posture.
π https://cloudsecurityalliance.org/star/
3οΈβ£ RiskRecon Free Tier β Provides risk ratings and supplier insights for SaaS applications.
π https://www.riskrecon.com/
4οΈβ£ AppOmni Free Plan β SaaS security posture assessment for collaboration apps and CRMs.
π https://www.appomni.com/
5οΈβ£ SaaS Security Alliance (SSA) Tools β Templates and guides for evaluating SaaS risk.
π https://www.saassecurityalliance.org/
6οΈβ£ OpenPages SaaS Risk Templates β Free templates for mapping SaaS applications to risk categories.
π https://www.ibm.com/products/openpages
7οΈβ£ CloudSploit Community Edition β Checks misconfigurations and risk in SaaS-integrated cloud services.
π https://github.com/aquasecurity/cloudsploit
β‘ Takeaway: Even free tools provide visibility, scoring, and actionable recommendations that help CISOs reduce shadow IT and prevent SaaS-related breaches.
At AUMINT.io, we complement these assessments by simulating how employees interact with SaaS apps and could be manipulated, exposing hidden human risks that automated tools may miss.
π Want to see where your human layer exposes SaaS risk? Book a free demo
#SaaSSecurity #CISO #CyberSecurity #SupplyChainRisk #AUMINT