#Pathlock
One of the big powers that Claremont and his crew had that these 90s writers don’t is the ability to introduce 12 bad guys all at once and they all kick ass. The Marauders, Reavers, etc. Every issue of this 90 stuff is like “Shalazam! Pathlock! Kyle-9! Kill the X-Men!” but they’re just some guys.
February 28, 2026 at 11:23 PM
Pathlock Achieves Recognition in 2026 Gartner Market Guide for Software Asset Management Tools#None#SAP#Pathlock#Software_Asset_Management
Pathlock Achieves Recognition in 2026 Gartner Market Guide for Software Asset Management Tools
Pathlock has been recognized in the 2026 Gartner Market Guide as a leading vendor for Software Asset Management tools, highlighting their impactful solutions.
third-news.com
February 2, 2026 at 3:10 PM
Pathlock Achieves SAP Certification for Clean Core Solutions with RISE#USA#Cyber_Security#Denver#SAP#Pathlock
Pathlock Achieves SAP Certification for Clean Core Solutions with RISE
Pathlock's certification for its Native Cyber Security and GRC Suite confirms alignment with SAP's Clean Core principles, enhancing security.
third-news.com
May 21, 2026 at 1:28 PM
The Rise of AI Agents in Financial Workflows Raises Governance Challenges for Enterprises#USA#Denver#AI_Governance#Pathlock#Financial_Workflows
The Rise of AI Agents in Financial Workflows Raises Governance Challenges for Enterprises
Discover the challenges enterprises face with AI agents taking on financial responsibilities, highlighting the urgent need for governance and oversight.
third-news.com
July 30, 2026 at 1:22 PM
🏛️ AI agents gain access to financial workflows amid growing governance gaps

📝 AI agents are now being allowed to create business records, ...

https://www.csoonline.com/article/4203384/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html

📰 CSO Online

#AI #AppSec
AI agents gain access to financial workflows amid growing governance gaps
A Pathlock report found that 53% of organizations cannot fully verify what AI agents do across business systems, even as they gain authority over finance, HR, procurement, and supply chain workflows.
www.csoonline.com
July 30, 2026 at 2:01 PM
AI agents gain access to financial workflows amid growing governance gaps
AI agents gain access to financial workflows amid growing governance gaps
A Pathlock report found that 53% of organizations cannot fully verify what AI agents do across business systems, even as they gain authority over finance, HR, procurement, and supply chain workflows.
www.csoonline.com
August 4, 2026 at 3:12 PM
AIエージェント、ガバナンス体制の不備を残したまま財務ワークフローへのアクセス権を拡大

Pathlockのレポートによれば、AIエージェントが財務・人事・調達・サプライチェーンの各ワークフローで権限を持つようになっている一方、組織の53%はビジネスシステム全体でAIエージェントが何を行っているかを完全には検証できていないことが分かりました。
AIエージェント、ガバナンス体制の不備を残したまま財務ワークフローへのアクセス権を拡大
Pathlockのレポートによれば、AIエージェントが財務・人事・調達・サプライチェーンの各ワークフローで権限を持つようになっている一方、組織の53%はビジネスシステム全体でAIエージェントが何を行っているかを完全には検証できていないことが分かりました。
blackhatnews.tokyo
July 30, 2026 at 1:08 PM
AI agents gain access to financial workflows amid growing governance gaps
AI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizations do not have a dedicated AI governance team, despite AI agents being increasingly plugged into business-critical operations like finance, procurement, HR, and supply chain applications. More than half of the organizations surveyed by Pathlock said they can’t fully verify actions AI agents execute across these business systems. “For decades, governance focused on controlling who could access a system,” said Susan Stapleton, GRC expert at Pathlock. “AI agents introduce a different challenge: understanding what actually happened after access was granted.” Being able to verify, trace, investigate, and explain AI-driven actions in real time across business applications will determine an organization’s AI preparedness, she added. ## Agents moving from copilots to financial operators The survey suggested enterprises are already trusting AI agents with responsibilities that until recently belonged exclusively to employees. Among surveyed respondents, 38% said AI agents can create or modify vendors and other business records, 35% allow them to execute cross-system workflows, and 28% permit them to approve transactions. More than one-third (36%) have already deployed, or are actively implementing, AI agents within finance and accounting environments. Most notably, about one in four organizations allow AI agents direct access to backend databases, Pathlock said in a report that CSO reviewed ahead of its publication. Chris Radkowski, another GRC expert at Pathlock, said three trends are converging simultaneously: the growth of machine identities, increasingly interconnected enterprise applications, and AI agents capable of executing business processes autonomously. The findings illustrate why machine identities are becoming a problem for security, said Crystal Morin, senior cybersecurity strategist at Sysdig. “As automation and AI-driven development explode, the gap between human and machine identities is becoming one of the defining security challenges of our time,” Morin said. “Businesses must treat machine identities as the new firewall.” ## Governance is still catching up While enterprises have begun introducing governance controls, the report argues most remain rooted in human-centric security models that focus on who receives access rather than what autonomous systems actually do after access is granted. Only 19% of organizations said they have complete, real-time visibility into AI agent activity across business systems, while 53% admitted they cannot fully verify AI-driven actions. Nearly half (48%) cannot trace AI activity end-to-end across multiple systems, making it difficult to reconstruct how an AI-driven outcome was produced. Investigation capabilities remain equally immature. Just 13% can investigate AI incidents in real time, while 22% cannot reliably investigate AI-driven actions at all. Ram Varadarajan, CEO at Acalvio, said traditional security approaches are unlikely to help. “General-purpose AI and traditional ‘check-the-box’ security audits are a false comfort when the actual battle is moving in milliseconds,” he said. “To maintain competitive edge and protect valuation, companies have to pivot from reactive defense to active, game-theoretic defense.”
www.csoonline.com
July 30, 2026 at 11:32 PM
Our chat with Pathlock's CEO, Piyush Pandey, brought to light the facets of digital transformation and impending risks, and how to implement access control with the zero trust model.

🔗Read the Interview⤵️

#RiskManagement #DigitalBusinessRisk #AccessControl #SegregationofDuties #SoD #SAP #IAM
Navigating Digital Transformation, Security Needs in Interconnected Workflows, and Preventing Transaction-Level Risks with Zero Trust
The CEO of Pathlock on transactional-level risk, access controls, SoD principles, and safeguarding business-critical apps like SAP.
www.technadu.com
June 12, 2025 at 5:46 PM
Pathlock Introduces Continuous Controls Monitoring to Reduce Time and Costs
Pathlock Introduces Continuous Controls Monitoring to Reduce Time and Costs
www.darkreading.com
March 20, 2024 at 7:37 PM
SAP-Schwachstellen gefährden Windows-Nutzerdaten
Schwachstellen in SAP GUI geben sensible Daten durch schwache oder fehlende Verschlüsselung preis. LALAKA – shutterstock.com Die Forscher Jonathan Stross von Pathlock, und Julian Petersohn von Fortinet warnen vor zwei neuen Sicherheitslücken in einer Funktion von SAP GUI, die für die Speicherung der Benutzereingaben in den Windows- (CVE-2025-0055) und Java-Versionen (CVE-2025-0056) zuständig ist . Dadurch werden sensible Informationen wie Benutzernamen, nationale ID-Nummern und Bankkontonummern gefährdet. Diese sind entweder unverschlüsselt oder mit einem schwachen, wiederverwendbaren XOR-Schlüssel geschützt, warnen die Forscher. „CVE-2025-0055 und CVE-2025-0056 stellen beide ein erhebliches Risiko für Unternehmen dar, das auf unsichere lokale Datenspeicherpraktiken zurückzuführen ist“, mahnt auch Mayuresh Dani, Security Research Manager bei Qualys. „Selbst wenn Passwortfelder aus dem Eingabeverlauf von SAP GUI ausgeschlossen sind, ist der Umfang der sensiblen Daten, auf die ein Angreifer zugreifen kann, sehr groß.“ SAP hat in Abstimmung mit dem Pathlock-Team im Januar 2025 stillschweigend relevante Sicherheitspatches und Abhilfemaßnahmen veröffentlicht, die nur für SAP-GUI-Kunden zugänglich sind. ## **Schwache XOR-Verschlüsselung ausnutzbar** Das Hauptproblem von CVE-2025-0055 ist ein einfacher Verschlüsselungsfehler. SAP GUI für Windows speichert zuvor eingegebene Werte wie Benutzer-IDs oder Sozialversicherungsnummern in einer lokalen SQLite-Datenbankdatei unter Verwendung einer exklusiven OR (XOR)-basierten Verschlüsselung. Die Verschlüsselung verwendet jedoch für jeden Eintrag denselben statischen Schlüssel, sodass ein einziger bekannter Wert ausreicht, um den Rest zu entschlüsseln. „Die Eingaben werden in einer SQLite3-Datenbankdatei (SAPHistory<WINUSER>.db) mit einem schwachen XOR-basierten Verschlüsselungsschema gespeichert, wodurch sie mit minimalem Aufwand leicht rückgängig gemacht werden können“, erklärte Stross von Pathlok in einem Blogbeitrag. CVE-2025-0056 basiert auf einen noch laxeren Ansatz in SAP GUI für Java, wo Verlaufsdaten völlig unverschlüsselt gespeichert werden. Das bedeutet, dass serialisierte Java-Objekte, die sensible Benutzereingaben enthalten, für jeden frei zugänglich sind, der Zugriff auf den Rechner hat. Laut Jason Soroko, Senior Fellow bei Sectigo, ist das Problem bei Java-Clients noch viel größer. „Der gleiche Verlauf wird als einfache, serialisierte Java-Objekte in plattformspezifische Ordner geschrieben – ohne jegliche Verschlüsselung“, betont der Experte. „Jeder, der lokalen oder Remote-Zugriff auf das Dateisystem eines gestohlenen Laptops, einer kompromittierten Workstation oder einer einfachen Phishing-Plattform erhält, kann die Verlaufsdateien sammeln. Damit ist er in der Lage, die laterale Bewegung zu beschleunigen, überzeugende Spear-Phishing-Angriffe zu erstellen oder Daten zu sammeln, die Compliance-Verstöße auslösen.“ Auch Pathlok warnt, dass die Schwachstellen trotz einer mittleren CVSS-Bewertung von 6 von 10 zu Compliance-Problemen führen könnten. Er verweist auf Risiken von Audit-Fehlern gemäß GDPR, PCI DSS oder HIPAA. SAP reagierte nicht auf Anfragen zu diesem Thema. ## **Die Spitze des Eisbergs?** Dani von Qualys merkte an, dass diese Schwachstellen zu weiteren gezielten Angriffen führen könnte. „Abgesehen davon, dass diese extrahierten Daten Angreifern genügend Munition für Spionageaktivitäten liefern, ermöglichen es die Schwachstellen, die Organisationsstruktur, Nutzungsmuster und Systemkonfigurationen zu verstehen. Angreifer können sie auch für personalisierte Angriffe wie Spear-Phishing nutzen, um einen bestimmten Benutzer effektiv zu kompromittieren und weitere Angriffe vorzunehmen“, so Dani. Die Untersuchungen von Pathlock führten auch zur Entdeckung einer ähnlichen Schwachstelle in SAP NetWeaver AS ABAP, die unter der Nummer CVE-2025-0059 erfasst wurde. Die Lücke betrifft SAP GUI für HTML, da sie auf dem gleichen Problem beruht. SAP hat diese Variante zwar noch nicht gepatcht, Pathlock befürchtet jedoch, dass ein Patch keine dauerhafte Lösung für diese Probleme ist. Laut Stross können Fallback-Mechanismen die von SAP veröffentlichten aktualisierten Versionen mit stärkerer Verschlüsselung – SAP GUI für Windows 8.00 Patch Level 9+ und SAP GUI für Java 7.80 PL9+ oder 8.10 – potenziell untergraben und unwirksam machen. Pathlock empfiehlt Unternehmen, den Eingabeverlauf vollständig zu deaktivieren, um das Risiko dauerhaft zu mindern. (jm)
www.csoonline.com
June 26, 2025 at 12:34 PM
SAP GUI flaws expose sensitive data via weak or no encryption
SAP GUI, a trusted interface for hundreds of thousands of global enterprises, has been found to be storing sensitive user data with outdated encryption, potentially allowing data breaches. According to Pathlock researcher Jonathan Stross and Fortinet’s Julian Petersohn, a couple of information disclosure vulnerabilities affect the product’s user input history feature in its Windows (CVE-2025-0055) and Java (CVE-2025-0056) versions. The newly disclosed vulnerabilities affect how user-entered data like usernames, national IDs, and bank account numbers are stored locally, either unencrypted or protected with a weak, reusable XOR key. “CVE-2025-0055 and CVE-2025-0056 both represent a significant organizational risk stemming from insecure local data storage practices,” said Mayuresh Dani, security research manager at Qualys. “Even though password fields are excluded from SAP GUI’s input history, the scope of exposed sensitive data that a threat actor can access is extensive.” SAP, in coordination with the Pathlock team, silently issued relevant security patches and mitigation steps in January 2025, accessible only to SAP GUI customers. ## Weak XOR encryption is exploitable At the heart of CVE-2025-0055 lies a simple encryption failure. SAP GUI for Windows stashes previously entered values, such as user IDs or SSNs, in a local SQLite database file using exclusive OR (XOR)-based encryption. However, the encryption uses the same static key for every entry, and a single known value is enough to decrypt the rest. “The inputs are saved in a SQLite3 database file (SAPHistory<WINUSER>.db) using a weak XOR-based encryption scheme, which makes them trivial to reverse with minimal effort,“ Pathlok’s Stross said in a blog post. CVE-2025-0056 revealed an even laxer approach in SAP GUI for Java, where history data is stored completely unencrypted. That means serialized Java objects holding sensitive user inputs can be freely accessed by anyone who can get onto the machine. The problem is much greater on Java clients, according to Jason Soroko, senior fellow at Sectigo. “The same history is written to platform‑specific folders as plain, serialized Java objects — no encryption at all,” he said. “Anyone who gains local or remote file‑system access to a stolen laptop, a compromised workstation, or to a simple phishing foothold can harvest the history files to accelerate lateral movement, craft convincing spear‑phishing, or amass data that triggers compliance violations.” Pathlok, too, warned that despite a medium CVSS rating of 6 out of 10, the flaws could lead to compliance issues, citing risks of audit failures under GDPR, PCI DSS, or HIPAA. SAP did not respond to queries on this matter. ## The impact could be much greater Dani noted that a breach through these vulnerabilities can facilitate further targeted attacks. “Not undermining the fact that this extracted data provides attackers with enough gunpowder for reconnaissance activities, a threat actor could comprehend organizational structure, usage patterns, and system configurations from the exploitation of these vulnerabilities and weaponize them for personalization attacks such as spear phishing to effectively compromise a targeted user and carry out further attacks,” Dani said. The Pathlock research also led to the discovery of a related flaw in SAP NetWeaver AS ABAP, tracked as CVE-2025-0059, affecting SAP GUI for HTML stemming from the same underlying issue. While SAP has yet to patch this variant, Pathlock is concerned that patching might not be a permanent fix to these issues. According to Stross, fallback mechanisms can potentially undermine the updated versions released by SAP with stronger encryption – SAP GUI for Windows 8.00 Patch Level 9+ and SAP GUI for Java 7.80 PL9+ or 8.10, making them ineffective. Pathlock recommends fully disabling input history to permanently mitigate the risk.
www.csoonline.com
June 25, 2025 at 10:30 PM
⬇WinIt Code for 08/21/2025⬇
WinIt Code: PathLock
🔗Follow us on our socials: Tap/Click HERE.

Login (or sign up for $5 bonus) to redeem the WinIt Code.

Expires 11:59pm CT on 08/21/2025

Like, comment or repost if the code worked!
#InboxDollars #WinIt #WinItCodes #BeermoneyCodes
Login (or sign up for $5 bonus) to redeem the WinIt Code.
🔗takes you to WinIt Code Redemption box if signed in
inboxdollars.sjv.io
August 21, 2025 at 12:04 PM