⤷ Title: Unlocking the Power of SAML: A Deep Dive into Seamless Single Sign-On
════════════════════════
𐀪 Author: Sagar Paul
════════════════════════
ⴵ Time: Sat, 18 Jan 2025 14:11:13 GMT
════════════════════════
⌗ Tags: #saml_authentication #cybersecurity #web_application_security #saml #sso
════════════════════════
𐀪 Author: Sagar Paul
════════════════════════
ⴵ Time: Sat, 18 Jan 2025 14:11:13 GMT
════════════════════════
⌗ Tags: #saml_authentication #cybersecurity #web_application_security #saml #sso
Medium
Unlocking the Power of SAML: A Deep Dive into Seamless Single Sign-On
Overview
⤷ Title: Understanding SAML (Security Assertion Markup Language)
════════════════════════
𐀪 Author: Paul Volosen
════════════════════════
ⴵ Time: Sun, 02 Feb 2025 02:58:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #saml
════════════════════════
𐀪 Author: Paul Volosen
════════════════════════
ⴵ Time: Sun, 02 Feb 2025 02:58:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #saml
Medium
Understanding SAML (Security Assertion Markup Language)
Introduction:
⤷ Title: SecOps in Action: Apache Guacamole w/ Okta Integration for Secure Remote Access
════════════════════════
𐀪 Author: TheMachine
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 23:54:16 GMT
════════════════════════
⌗ Tags: #saml #okta #secops #apache_guacamole #cybersecurity
════════════════════════
𐀪 Author: TheMachine
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 23:54:16 GMT
════════════════════════
⌗ Tags: #saml #okta #secops #apache_guacamole #cybersecurity
Medium
SecOps in Action: Apache Guacamole w/ Okta Integration for Secure Remote Access
Why Bother with Apache Guacamole?
⤷ Title: Attacking and Defending SAML
════════════════════════
𐀪 Author: Teri Radichel
════════════════════════
ⴵ Time: Wed, 19 Mar 2025 18:41:00 GMT
════════════════════════
⌗ Tags: #saml #pentesting #security #penetration_testing #idp
════════════════════════
𐀪 Author: Teri Radichel
════════════════════════
ⴵ Time: Wed, 19 Mar 2025 18:41:00 GMT
════════════════════════
⌗ Tags: #saml #pentesting #security #penetration_testing #idp
Medium
Attacking and Defending SAML
Obtaining the ultimate goal — authenticating as any user
⤷ Title: Critical Risk (CVSS 9.9): samlify Flaw Exposes SSO in Widely Used Library
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 02:39:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication #CVE_2025_47949 #SAML #samlify #security #Single Sign_On #SSO
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 20 May 2025 02:39:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication #CVE_2025_47949 #SAML #samlify #security #Single Sign_On #SSO
Daily CyberSecurity
Critical Risk (CVSS 9.9): samlify Flaw Exposes SSO in Widely Used Library
Critical vulnerability (CVSS 9.9) in samlify! This flaw puts many SSO implementations at risk, affecting a library with 768,000+ monthly downloads.
⤷ Title: Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
Daily CyberSecurity
Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
A critical flaw (CVE-2025-54369) in Node-SAML allows attackers to bypass SAML 2.0 authentication by manipulating unsigned assertion data. Update to v5.1.0 immediately!
⤷ Title: Critical Node-SAML Flaw (CVE-2025-54419, CVSS 10.0) Allows Authentication Bypass in SAML 2.0 Web Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 00:45:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cybersecurity #Node_SAML #Node.js #SAML 2.0 #Single Sign_On #SSO #Vulnerability #web applications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 00:45:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cybersecurity #Node_SAML #Node.js #SAML 2.0 #Single Sign_On #SSO #Vulnerability #web applications
Daily CyberSecurity
Critical Node-SAML Flaw (CVE-2025-54419, CVSS 10.0) Allows Authentication Bypass in SAML 2.0 Web Apps
A critical vulnerability (CVE-2025-54419, CVSS 10.0) in Node-SAML allows attackers to bypass SAML 2.0 authentication by manipulating unsigned assertion data.
⤷ Title: SUSE Rancher Security Team Patches Three Vulnerabilities in Rancher Manager
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 02:16:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2024_58267 #cybersecurity #Denial of Service #Information Leakage #Kubernetes #Rancher Manager #SAML Phishing #security update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 02:16:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2024_58267 #cybersecurity #Denial of Service #Information Leakage #Kubernetes #Rancher Manager #SAML Phishing #security update
Daily CyberSecurity
SUSE Rancher Security Team Patches Three Vulnerabilities in Rancher Manager
SUSE patches three flaws in Rancher Manager. A phishing vulnerability (CVSS 8.1) can steal admin tokens, while a DoS flaw can lock out administrators.
⤷ Title: Authentication Bypass: Mis-scoped SAML Sessions Enable User Impersonation
════════════════════════
𐀪 Author: Abdo Rabea (0xOverlord)
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 09:51:38 GMT
════════════════════════
⌗ Tags: #authentication #saml #bug_bounty_writeup #bug_bounty #authentication_bypass
════════════════════════
𐀪 Author: Abdo Rabea (0xOverlord)
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 09:51:38 GMT
════════════════════════
⌗ Tags: #authentication #saml #bug_bounty_writeup #bug_bounty #authentication_bypass
Medium
Authentication Bypass: Mis-scoped SAML Sessions Enable User Impersonation
at Public Bug Bounty Program
⤷ Title: Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
Daily CyberSecurity
Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
Jenkins warned of a Critical SAML Plugin flaw (CVE-2025-64131) that allows session replay/hijacking due to a missing cache. Multiple plugins also expose API tokens in plaintext.
⤷ Title: Critical Fortinet Flaw Risks Unauthenticated Admin Bypass via FortiCloud SSO SAML Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59718 #FortiCloud #Fortinet #FortiOS #SAML Forgery #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59718 #FortiCloud #Fortinet #FortiOS #SAML Forgery #SSO Bypass
Daily CyberSecurity
Critical Fortinet Flaw Risks Unauthenticated Admin Bypass via FortiCloud SSO SAML Forgery
Fortinet has issued an urgent security advisory following the discovery of a critical vulnerability affecting its flagship network security products. The flaw, which carries a critical CVSS score …
⤷ Title: Critical FortiGate SSO Flaw Under Active Exploitation: Attackers Bypass Auth and Exfiltrate Configs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:58:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Authentication Bypass #CVE_2025_59718 #FortiCloud #FortiGate #Fortinet #SAML #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:58:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Authentication Bypass #CVE_2025_59718 #FortiCloud #FortiGate #Fortinet #SAML #SSO Bypass
Daily CyberSecurity
Critical FortiGate SSO Flaw Under Active Exploitation: Attackers Bypass Auth and Exfiltrate Configs
A critical FortiGate SSO flaw (CVSS 9.1) is under active exploitation, letting unauthenticated attackers bypass login via crafted SAML. The flaw is armed by default registration, risking config exfiltration. Patch immediately.
⤷ Title: The SSO Trap: How a “Default” Feature is Granting Attackers Admin Access to FortiGate Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
Penetration Testing Tools
The SSO Trap: How a "Default" Feature is Granting Attackers Admin Access to FortiGate Devices
Arctic Wolf reports the first confirmed intrusions into customer networks in which attackers logged into FortiGate devices via
⤷ Title: Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
Information Security News
Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
SAMLSmith is a C# tool for generating custom SAML responses and implementing Silver SAML and Golden SAML attacks. It provides comprehensive functionality for security researchers and penetration t…
⤷ Title: Surgical Silence: The New Fortinet Zero-Day That Hijacks Firewalls in Seconds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:54:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #cloud_init@mail.io #CVE_2026_24858 #FortiCloud SSO #FortiGate #Fortinet #SAML exploit #secadmin #zero_day 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:54:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #cloud_init@mail.io #CVE_2026_24858 #FortiCloud SSO #FortiGate #Fortinet #SAML exploit #secadmin #zero_day 2026
Penetration Testing Tools
Surgical Silence: The New Fortinet Zero-Day That Hijacks Firewalls in Seconds
Cybersecurity specialists at Arctic Wolf have identified a nascent wave of incursions targeting Fortinet FortiGate firewalls. Adversaries are