#SSO
5 stories taggedSSO.

Critical Keycloak Bug Lets Anyone Reset Your Password and Log In as You
A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

Zero Trust Turns 15 and Still Can't Get Out of Its Own Way
The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

Shadow Builders: When Employees Ship Production Apps Without Auth
Vibe-coded internal tools are graduating to public URLs, and most identity stacks never see them coming.