New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems
ID: 98f52e4d-791f-56c7-b433-bf4a7c26860a
STIX ID: report--98f52e4d-791f-56c7-b433-bf4a7c26860a
Feed Name: The Hacker News
**Executive Summary:** Silver SAML is a newly disclosed SAML-forgery technique against identity providers such as Microsoft Entra ID that allows an attacker who obtains the private key of an externally generated SAML signing certificate to forge SAML responses and access federated applications; Semperis published a PoC, Microsoft does not consider the issue an immediate servicing risk, and recommended mitigations include using Entra ID self-signed certificates and monitoring PreferredTokenSigningKeyThumbprint rotations in audit logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
