📊 Key Data
  • 210% increase in active exploitation of SAP vulnerabilities in 2025
  • 87% of real-world vulnerabilities successfully exploited by AI agents in recent study
  • CVE-2025-31324 (CVSS 10.0) exploited by at least 10 threat clusters before patch release
🎯 Expert Consensus

Experts agree that AI is significantly lowering the barrier to entry for cybercrime, enabling faster and more sophisticated attacks on critical enterprise systems like SAP applications, requiring immediate proactive defense strategies.

about 1 month ago
AI Arms Cybercriminals Targeting Core Enterprise Systems

AI Arms Cybercriminals Targeting Core Enterprise Systems

BOSTON, MA – June 16, 2026 – The barrier to entry for high-stakes cybercrime is collapsing. Financial institutions and global corporations are facing a new breed of threat, one where sophisticated attacks on their most critical enterprise systems no longer require elite hacking skills. The culprit is artificial intelligence, which is rapidly being weaponized to target the digital backbone of the global economy: SAP applications.

Highlighting this urgent threat, SAP cybersecurity leader Onapsis announced it will debut a new episode in its docuseries, “Hacking and Defending SAP Applications,” on June 25. Titled “When AI Attacks SAP,” the episode promises to demonstrate how threat actors are leveraging frontier AI models to map vulnerabilities, generate exploits, and execute complex attacks against the business-critical software that manages everything from financials to supply chains.

“AI is democratizing cybercrime and lowering the barrier to entry for threat actors to infiltrate enterprise applications, leading to faster and more sophisticated attacks and more vulnerabilities, creating the perfect storm in the threat landscape,” said Mariano Nunez, CEO and Co-Founder of Onapsis, in a recent statement. The company’s initiative aims to arm defenders with the crucial knowledge of how these new AI-driven attack vectors function.

The Escalating Threat to SAP's Fortress

The warning comes at a time of unprecedented volatility for SAP security. According to Onapsis, last year saw a staggering 210% increase in the active exploitation of SAP vulnerabilities. This alarming trend is not an isolated claim. Independent analysis from Mandiant’s M-Trends 2026 report corroborates the severity of the situation, identifying the infamous SAP NetWeaver zero-day vulnerability (CVE-2025-31324) as the most exploited vulnerability of 2025.

This particular flaw, which carried a maximum CVSS severity score of 10.0, allowed unauthenticated attackers to upload malicious files and achieve remote code execution, granting them a direct path to full system compromise. At least four distinct threat clusters exploited the vulnerability before an emergency patch was even released, with six more, including suspected state-sponsored groups, joining the fray after its public disclosure. The incident underscores a critical reality: the window between vulnerability discovery and mass exploitation is shrinking dramatically, leaving unprepared organizations dangerously exposed.

How AI Democratizes Cybercrime

Historically, attacking complex SAP environments required deep, specialized knowledge of proprietary protocols and architecture. AI is changing that equation. Large language models (LLMs) and other generative tools act as a potent “force multiplier,” empowering even novice attackers to operate with a level of sophistication previously reserved for well-funded hacking groups.

Research has demonstrated that AI agents can autonomously analyze public vulnerability descriptions (like those in CVE reports) and successfully generate functional exploits. One recent study found that such agents could exploit 87% of the real-world vulnerabilities they were tested against, effectively automating the most technical phase of an attack. This capability drastically reduces the time, cost, and expertise needed to turn a theoretical flaw into a practical breach.

Onapsis, which has attracted over 1,300 IT and security professionals to its docuseries, aims to pull back the curtain on these methods. “Theoretical knowledge is great, but to truly protect an enterprise, security teams need to understand the ‘how’ behind the attacks that are targeting them,” noted Juan Pablo Perez-Etchegoyen, the company's Chief Technology Officer. Their forthcoming episode will feature real-world scenarios of AI mapping SAP application vulnerabilities and breaching the core.

A New Paradigm for Institutional Defense

The implications extend far beyond SAP. Law enforcement agencies like the FBI and Europol have issued stark warnings about AI’s role in accelerating organized crime, from generating hyper-realistic phishing campaigns to automating fraud. For institutional investors and financial market analysts, this trend signals a fundamental shift in operational risk. The speed and scale of AI-driven attacks challenge traditional security postures that rely on quarterly patch cycles and reactive incident response.

To counter this evolving threat, organizations must adopt a more proactive, continuous, and intelligent defense strategy. This begins with abandoning outdated vulnerability management timelines in favor of accelerated patching and automated scanning to close security gaps before they can be weaponized. For institutions leveraging AI to generate custom code for their SAP systems, a robust Secure Software Development Lifecycle (SSDLC) is no longer optional; it is essential to prevent AI models from inadvertently introducing old vulnerabilities into new applications.

Building a Resilient Digital Core

Protecting the enterprise requires integrating SAP security into the broader cybersecurity ecosystem. This means feeding SAP event logs into central SIEM and SOC platforms for real-time monitoring and anomaly detection. It also involves adhering to established security frameworks. The NIST Cybersecurity Framework, for example, provides a structured methodology for managing risk in SAP environments, and its new draft AI Cybersecurity Framework Profile offers specific guidance for defending against AI-powered attacks.

Furthermore, as companies migrate to cloud environments like RISE with SAP, they must rigorously manage their side of the shared responsibility model, securing application layers, data, and the myriad of APIs and integrations that connect SAP to the outside world. Misconfigured interfaces remain a primary entry point for attackers.

Ultimately, the rise of AI as an offensive tool demands a commensurate evolution in defensive strategy. By understanding the attacker’s new playbook, institutions can begin to fortify their digital core, moving from a reactive stance to one of proactive resilience against the next frontier of cyber threats.

Topics & Related

Event:
Regulatory & Legal
Industry Conference
Product Launch
Metric:
Risk & Leverage
Product:
AI & Software Platforms
Sector:
Banking
AI & Machine Learning
Software & SaaS
Theme:
Agentic AI
Generative AI
Zero Trust
Threat Landscape
UAID: 36333