logo

JamfHound v1.1 Update: SSO Attack Paths and Okta Additions

ID: ba50ac28-79d6-5704-b1a3-61b3b67a6b69

STIX ID: report--ba50ac28-79d6-5704-b1a3-61b3b67a6b69

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-05-01

...
...

This report describes JamfHound v1.1 enhancements that add SSO-aware graph nodes and hybrid edges to BloodHound, enabling visibility of dangerous attack paths in JAMF Pro deployments integrated with external identity providers (e.g., Okta). The updates reveal practical privilege escalation scenarios—such as abusing the "Update SSO Settings" right to point JAMF to an attacker-controlled IDP, and leveraging Okta–JAMF device/group mappings—to achieve full admin access and cross-platform pivoting; defenders can use the collector to identify and remediate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.