• Skip to primary navigation
  • Skip to content
  • Skip to footer
KWM
  • About
  • Archive
    by Keith McCammon

    by Keith McCammon

    • LinkedIn
    • Twitter
    • GitHub
    • Feed
    /* real people should not fill this in and expect good things - do not remove this or risk form bot signups */

    SaaS attack technique matrix

    August 25, 2024

    Inspired by MITRE ATT&CK, the good folks at Push Security have taken a pass at enumerating attack techniques specific to Software-as-a-Service (SaaS) applications.

    ATT&CK is a great and robust framework, and I love to see it adapted to capture techniques and tactics for different types of systems.

    Push Security SaaS Attacks example

    Discussion: LinkedIn

    Direct Link

    Categories: Links

    Updated: August 25, 2024

    Previous Next

    You May Also Enjoy

    NFL streaming cheat sheet for 2026-2027

    August 31, 2026

    NFL season is upon us, and the number of standalone, prime time, and international games that require a streaming provider stands at 43: Peacock (20), Amazon Prime (16), Netflix (5), Paramount+ (2).

    Intrusion observations mid-2026

    August 18, 2026

    Two trends have persisted for 2–3 years and are now fully reflected in everything from industry and breach reporting to the market for cybersecurity talent and solutions:

    Frontier AI models and regulatory capture

    June 26, 2026

    Regulatory capture of frontier AI models would be an absolute gift to the ecosystem of companies blessed to use them. Here’s a directly related prediction from Steve Yegge on June 18, 2026:

    Assorted links 2026-05-19

    May 19, 2026

    Exploits don’t cause cyberattacks: On thinking clearly about frontier AI advances and cyber conflict - “[M]ost of today’s attacker constituencies can currently achieve most of their desired outcomes using traditional means: simple phishing, credential stuffing, exploitation of known CVEs, etc. These constituencies aren’t likely to explode into hockey-stick adoption of AI vulnerability research tools. ❡ This should discipline our thinking about Mythos generating a discontinuous volume of cyberattacks, because, again, most attacker constituencies just aren’t blocked by vulnerability research for most of their workflows.”

    • LinkedIn
    • Twitter
    • GitHub
    • Feed
    © 2026 KWM. Powered by Jekyll & Minimal Mistakes.