-

Obsidian Security Releases Industry-First SaaS Session Hijacking Detection Feature to Protect Today’s Cloud-First Organizations

New feature enables early detection of session hijacking attempts in SaaS applications such as Okta and Azure AD to mitigate threats that bypass MFA

NEWPORT BEACH, Calif.--(BUSINESS WIRE)--Obsidian Security, the leader in SaaS Security and Posture Management (SSPM), unveiled the ability to detect SaaS session hijacking attempts early in the kill chain across multiple platforms like Okta, Azure AD, Microsoft 365 and more. The capability is used by more than 80 customers worldwide, including eight customers in the Fortune 1000. Attackers have recognized that credential stealing is less effective due to the broad adoption of multi-factor authentication (MFA) by organizations today. However, tokens associated with sessions of SaaS applications can be reused within time limits to access any and all applications associated with the identity provider (IDP), which is exemplified in the recent breach at Okta. In addition, Obsidian is expanding its comprehensive posture management capabilities to support ServiceNow, which joins an already expansive portfolio of SaaS applications including Microsoft 365, Salesforce, GitHub, Workday, Atlassian, etc.

94% of enterprises depend on cloud services and SaaS apps to operate in today’s modern, hybrid workforce, complete daily tasks, and store sensitive information. When an IDP is breached, this results in access to all SaaS applications and sensitive data behind them as well. There is a shared responsibility that needs to be recognized between application vendors, the security team and lines-of-business owners to ensure that all SaaS applications are protected in an organization’s network.

Sophisticated attacks are becoming more common for cloud-first organizations today, so taking precautions to prevent session hijacking via identity providers like Okta and Azure AD with Obsidian’s new offering are critical. The unique aspect of our session hijacking detection was it came through 18 months of work directly with the red team at one of our customers. “In today's dynamic world, where architecture and infrastructure changes are constant and new threats pop-up daily, having a red team that can emulate real-world threat actors and identify areas vulnerable to attack, is worth every penny.” said Snowflake Vice President of Security Mario Duarte. You can learn more about Obsidian's session hijacking feature here.

“Too often, organizations rely on out-of-the-box security protection for the slew of mission-critical SaaS apps deployed in their networks, including their IDP, but that is no longer sufficient in today’s environment,” said Glenn Chisholm, CPO and Co-founder at Obsidian. “Now, with our new preventative session hijacking feature, security leaders and teams have more comprehensive protection of their IDP and SaaS apps, beyond the endpoints alone, and a better understanding of where cyber risk exists within their digital infrastructure to prevent future exploits and sophisticated attacks that bypass MFA.”

About Obsidian Security

Obsidian Security is the first truly comprehensive threat and posture management solution built for SaaS. Our platform consolidates data across core applications to help your team optimize configurations, reduce over-privilege, and mitigate account compromises and insider threats. The company was founded in 2017 by industry experts from Carbon Black and Cylance including Ben Johnson, Glenn Chisholm and Matt Wolff. Notable Fortune 500 companies trust Obsidian Security to secure SaaS apps and tools, like GitHub, Salesforce, Microsoft 365, ServiceNow, Workday, Google Workspace and Atlassian. Headquartered in Southern California, Obsidian Security is a privately held company and is backed by Greylock Partners, GV, Norwest Venture Partners, and Wing. For more information, visit www.obsidiansecurity.com.

Contacts

Jill Creelman
Obsidian@inkhouse.com

Obsidian Security


Release Versions

Contacts

Jill Creelman
Obsidian@inkhouse.com

More News From Obsidian Security

Obsidian Security Ranked Among the Fastest-Growing Companies in North America on the 2025 Deloitte Technology Fast 500™

PALO ALTO, Calif.--(BUSINESS WIRE)--Obsidian Security, leader in SaaS security, today announced it ranked No. 95 on the 2025 Deloitte Technology Fast 500™, a ranking of the 500 fastest-growing technology, media, telecommunications, life sciences, fintech, and energy tech companies in North America. Obsidian Security grew close to 1000% during the 2021–2024 period. Obsidian Security’s Chief Executive Officer, Hasan Imam, credits the company’s accelerated growth to relentless focus on SaaS and AI...

Obsidian Closes the SaaS Security Coverage and Intelligence Gap Amid Expanding Attack Surface

PALO ALTO, Calif.--(BUSINESS WIRE)--Obsidian Security, leader in SaaS security, today announced a major expansion of its platform to secure the next frontier of SaaS and AI. The release brings together community-built integrations, deep data context, and AI-driven intelligence to help organizations secure their expanding SaaS environment at enterprise scale. SaaS has become the backbone of the modern enterprise and attackers are moving faster than most security teams can respond. SaaS breaches...

Obsidian Security Unveils AI Agent Defense to Secure SaaS Data Access

PALO ALTO, Calif.--(BUSINESS WIRE)--Obsidian Security Unveils AI Agent Defense to Secure SaaS Data Access...
Back to Newsroom