highGlobalMultiScattered Spider
Impact
Ticketmaster, Santander, AT&T, dll terdampak.
Initial vector
Stealer creds → SaaS tanpa MFA
Lessons learned
- MFA SaaS wajib
- Network policy SaaS
- Stealer monitoring
Kredensial pengguna SaaS hasil infostealer dipakai akses ratusan tenant Snowflake.