Skip to main content
Case Study

Golden SAML: Newly Discovered Attack Technique Forges Authentication to Cloud Apps

<h1><span style="font-size:11.0pt"><span style="font-family:&quot;Calibri&quot;,sans-serif">In this blog post, we introduce a new attack vector discovered by CyberArk Labs and dubbed &ldquo;golden SAML.&rdquo; The vector enables an attacker to create a golden SAML, which is basically a forged SAML &ldquo;authentication object,&rdquo;<em> </em>and authenticate across every service that uses SAML 2.0 protocol as an SSO mechanism. </span></span></h1>

1 min read0 views
Share:

In this blog post, we introduce a new attack vector discovered by CyberArk Labs and dubbed “golden SAML.” The vector enables an attacker to create a golden SAML, which is basically a forged SAML “authentication object,” and authenticate across every service that uses SAML 2.0 protocol as an SSO mechanism.

 

DOWNLOAD PDF HERE