Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

University of Pennsylvania breach highlights SSO security risks

The University of Pennsylvania breach demonstrates the high-impact risk of a compromised single sign-on (SSO) account, which served as a centralized attack vector to infiltrate multiple internal systems including VPN, Salesforce, and SharePoint. This incident underscores that SSO security is contingent on robust foundational controls, specifically the enforcement of strong, lengthy passwords and phishing-resistant multi-factor authentication (MFA) for all users. Organizations must also rigorously secure their identity provider's administrative components, such as signing certificates and OAuth secrets, to mitigate the widespread damage possible from stolen SSO credentials.
Read Full Article →

Identity , SSO/MFA University of Pennsylvania breach highlights SSO security risks July 29, 2026 Share By SC Staff (Adobe Stock) As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account, underscoring the concentrated risks associated with this convenient authentication method. Attackers gained access to a PennKey SSO account, which then allowed them to infiltrate internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. This breach resulted in the theft of data belonging to 1.2 million individuals. While SSO offers benefits like reduced password sprawl and centralized access policies, its security hinges on robust protection. The university's incident highlights the need for strong passwords, with NIST recommending at least 15 characters for single-factor authentication and 8 characters for passwords used with multi-factor authentication (MFA). Furthermore, MFA should be consistently enforced across all users and access scenarios, moving beyond less secure methods like SMS codes towards phishing-resistant options such as FIDO2 security keys. Organizations must also secure the identity provider (IdP) administrator accounts, signing certificates, keys, and OAuth secrets, as well as review consent grants and delegated permissions to mitigate risks associated with compromised SSO credentials. Source: Bleeping Computer SC Staff Related Threat Intelligence CAF Bank suspends online services due to third-party software vulnerability SC Staff July 29, 2026 As outlined in The Register, CAF Bank, which serves approximately 14,000 charities, temporarily suspended its online banking services to address a security vulnerability. AI/ML Loss of control: The AI agent governance crisis Paul Wagenseil July 29, 2026 AI governance is an identity challenge, but legacy identity systems weren't made to handle non-deterministic software. Identity German government report details Windows Hello for Business biometric security limitations SC Staff July 28, 2026 Germany’s Federal Office for Information Security (BSI) published a technical analysis of Windows Hello for Business, detailing how the system performs biometric identification and highlighting potential security vulnerabilities. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) False Rejects You can skip this ad in 5 seconds

Share this article