search

The Fragile Lock: Novel Bypasses For SAML Authentication

source Source: PortSwigger Research
calendar_today
schedule 1 min read

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi

Related articles

cybersecurity

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

cybersecurity

Australian energy provider Origin says data breach exposes client data

Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others.

cybersecurity

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.