SAP
Disclosed Jul 17, 20242 years agoUnverified
SAPwned: SAP AI Core flaws gave researchers access to customer cloud keys and AI artifacts
Wiz researchers ran malicious training jobs on SAP AI Core and chained isolation flaws to gain cluster admin rights, read and modify SAP container images and artifacts, and reach customers' private files and AWS, Azure and HANA credentials. SAP fixed the issues and Wiz said no customer data was compromised.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 17, 2024 |
| Attack | Exposed data |
| Data exposed | Credentials and tokens, API keys, Training data |
| Sector | Tech · DE |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 17, 2024 |
Other breaches at SAP
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Official SAP npm packages trojanized to steal developer credentialsApr 294 months agoSupply chainUnverified | Apr 294 months ago | Supply chain | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.