bleeping-computer · Crawled Jul 28, 2026

Is Your SSO Protected Against Modern Credential Attacks?

Read original article ↗

AI Summary

The article discusses the risks associated with single sign-on (SSO) systems, highlighting the 2025 University of Pennsylvania breach where attackers compromised a PennKey SSO account and accessed internal systems such as VPN, Salesforce, Qlik, SAP, and SharePoint, leading to the theft of data on 1.2 million individuals. It emphasizes that while SSO improves user experience and centralized access management, it must be properly secured with strong passwords and multi-factor authentication (MFA) to prevent credential-based attacks. The article recommends using phishing-resistant MFA, securing identity provider (IdP) administrator accounts, and protecting signing certificates, OAuth secrets, and delegated permissions to reduce the identity attack surface.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.