Tech News
← Home  ·  All topics

Single Sign-On

3 GoKawiil briefs on this topic

Security researchers argue SAML authentication protocol should be retired for OpenID Connect

A security industry blog post traces SAML's origins as a 2002 OASIS committee standard built on XML, arguing it powered the early single sign-on industry but has since become overly complex and fragile. The piece, citing security researcher Thomas Ptacek, contends SAML's reliance on XML signature validation makes real-world implementations difficult to secure, and calls for organizations to move to newer alternatives like OpenID Connect (OIDC).

ShinyHunters-linked hackers use fake passkey alerts to breach Microsoft 365 accounts

Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.

Dropbox says 5,000 accounts breached via flawed Lenovo SSO login

Dropbox notified users that roughly 5,000 accounts were accessed without authorization between August 4 and 21, 2026, with files downloaded from about 1,500 of them. The breach traces to a single sign-on integration with Lenovo IDs, where a gap in Lenovo's email verification let attackers register accounts under victims' email addresses and log into their Dropbox accounts without needing inbox access.