SAML: 잘못된 설계의 프랙털
SAML의 복잡성이 증가하면서 OpenID Connect로의 전환이 필요하다.
The complexity of SAML increases the need for a transition to OpenID Connect.
AI가 선별한 아티클
SAML의 복잡성이 증가하면서 OpenID Connect로의 전환이 필요하다.
The complexity of SAML increases the need for a transition to OpenID Connect.
NCP 외부 접근을 위한 비공식 TS·Go 인증 라이브러리 개발 소식.
Announcement of an unofficial TS·Go authentication library for NCP external access.
패스키의 장점과 단점에 대해 논의합니다.
Discusses the advantages and disadvantages of passkeys.
시스코, ISE에서 새로운 제로데이 취약점 경고.
Cisco warns of a new zero-day vulnerability in ISE.
N0va가 미국과 유럽 기업을 대상으로 피싱 캠페인을 진행하고 있습니다.
N0va is targeting US and EU businesses with phishing campaigns.
피싱 공격의 원인은 사용자나 DNS가 아니라 기업 로그인 방식에 있다.
Phishing attacks result from corporate login methods, not users or DNS.
AI가 보안팀에 취약점을 넘쳐나게 하며, 비즈니스 맥락이 우선 순위를 설정한다.
AI inundates security teams with flaws, underscoring business context for prioritization.
에어비앤비는 서버 구동 아키텍처로 인증 코드를 60% 줄였습니다.
Airbnb reduced authentication code by 60% with a server-driven architecture.
PaperCut NG 및 MF의 취약점을 통해 인증 없이 코드 실행이 가능해졌다.
PaperCut NG and MF vulnerabilities exploited to execute code without authentication.
miniOrange SAML의 취약점으로 공격자가 WordPress 관리자 권한을 획득할 수 있음.
miniOrange SAML vulnerabilities allow attackers to gain WordPress admin access.
Citrix가 NetScaler ADC 및 Gateway의 심각한 인증 우회 취약점을 수정했습니다.
Citrix has released updates for critical authentication bypass flaws in NetScaler ADC and Gateway.
해커들이 14,500개 이상의 Dahua 장치를 침해한 사건이 보고됐다.
Hackers compromised over 14,500 Dahua devices in a reported incident.
Airbnb가 Flexible Authentication을 통해 인증 방식을 재설계했습니다.
Airbnb redesigned authentication with Flexible Authentication.
새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.
Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.
새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.
New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.
DoorDash는 AI 에이전트의 도구 접근을 위한 중앙 게이트웨이를 구축하였다.
DoorDash built a centralized gateway for AI agent tool access.
Kali365가 마이크로소프트 인증을 악용하여 기업 데이터를 위협하고 있다.
Kali365 weaponizes Microsoft authentication to threaten corporate data access.
공유 인증 라이브러리의 버그를 해결한 경험담
A story about fixing a bug in a shared authentication library.
구글 비밀번호 관리자 공격이 패스키 보호 계정을 위험에 빠뜨릴 수 있음.
Google Password Manager vulnerabilities could let malware access passkey-protected accounts.
Tailscale의 보안 문제가 Hugging Face의 데이터 침해를 초래했다.
Tailscale's security issues led to a data breach at Hugging Face.
24,650개의 인터넷에 노출된 BMC가 로그인 전 패스워드 해시를 공개함.
24,650 internet-exposed BMCs disclose password hashes before login.
패스키에 대한 간단한 설명과 이점에 대한 글입니다.
A simple explanation of passkeys and their benefits.
1Password의 새로운 브라우저 통합 기능이 AI의 자격 증명 사용 방식을 변화시킵니다.
1Password's new browser integration changes how AI uses credentials.
n8n의 취약점으로 인해 사용자가 다른 발급자로 로그인할 수 있는 문제 발생.
n8n's vulnerability allows attackers to log in as users from another issuer.
스위스 AGOV 시스템이 프랑스식 키보드의 숫자 입력을 지원하지 않는 문제.
Switzerland's AGOV system fails to handle numeric input from AZERTY keyboards.
Tenda 펌웨어에서 숨겨진 인증 백도어 발견.
Hidden authentication backdoor found in Tenda firmware.
AI 생성 코드의 보안 문제와 바이브코더를 위한 예방 방법을 설명합니다.
Highlights security issues in AI-generated code and prevention methods for coders.
SSO 기능에 대한 불합리한 비용 청구에 대한 비판.
Critique of the unreasonable charges for SSO features.
오라클 E-Business Suite의 취약점 CVE-2026-46817이 현재 활발히 악용되고 있다.
A critical flaw CVE-2026-46817 in Oracle E-Business Suite is actively being exploited.
AI 에이전트의 신원 문제는 보안 검토에서 발생하는 도전과제에 대해 논의합니다.
Discusses the challenges of AI agent identity issues that arise during security review.