<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: SAP Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving SAP.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record</title><link>https://cyberscoop.com/microsoft-patch-tuesday-july-2026</link><guid isPermaLink="false">cst-2535</guid><description>Microsoft disclosed 622 vulnerabilities during July 2026 Patch Tuesday, more than triple the previous month's record of 206 and reflecting an exponential surge driven by artificial intelligence tools discovering defects at scale. Two actively exploited zero-day vulnerabilities in Active Directory Federation Services and SharePoint Server were included among the batch, with 63 rated as critical. The pace suggests Microsoft will exceed 2,000 or more Common Vulnerabilities and Exposures (CVEs) for the calendar year, far surpassing historical annual records.</description><pubDate>Tue, 14 Jul 2026 20:05:46 GMT</pubDate></item><item><title>SAP warns of critical flaws in NetWeaver and Commerce Cloud</title><link>https://bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud</link><guid isPermaLink="false">cst-2474</guid><description>The vendor released security updates addressing 16 vulnerabilities across multiple products in July 2026, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The updates cover significant exposure in SAP's enterprise middleware and cloud commerce platforms.</description><pubDate>Tue, 14 Jul 2026 11:42:21 GMT</pubDate></item><item><title>AWS gives its ERP agent deny-by-default rules and a separate identity</title><link>https://helpnetsecurity.com/2026/07/10/aws-agentic-ai-erp-automation</link><guid isPermaLink="false">cst-2305</guid><description>AWS has released enhancements to its ERP agent that include deny-by-default authorization rules and a separate identity mechanism. These improvements aim to address security concerns while allowing the agent to automate exception handling in enterprise resource planning workflows across finance operations.</description><pubDate>Fri, 10 Jul 2026 05:00:52 GMT</pubDate></item><item><title>Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware</title><link>https://wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm</link><guid isPermaLink="false">cst-1299</guid><description>Security researchers identified malicious npm packages associated with a supply chain campaign targeting SAP environments, distributing credential-stealing malware. The campaign, termed Mini Shai Hulud, represents an evolution of previous supply chain attack tactics focusing on development dependency chains.</description><pubDate>Wed, 29 Apr 2026 15:14:27 GMT</pubDate></item><item><title>SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts</title><link>https://wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security</link><guid isPermaLink="false">cst-1572</guid><description>Wiz Research identified vulnerabilities in SAP AI Core that could allow attackers to take control of the service and access customer data and private AI artifacts stored within cloud environments.</description><pubDate>Wed, 17 Jul 2024 17:45:17 GMT</pubDate></item></channel></rss>