search
Single Sign-On
Trends
- 1Bromcom discloses personal data breach tied to single sign-on system▼Bromcom notifies customers of personal data breach affecting SSO technology
Education software provider Bromcom has notified its customers that a personal data breach occurred involving its single sign-on technology. The company said affected individuals are being informed, though the number of people impacted and the nature of the compromised data have not yet been detailed. Bromcom supplies management information systems to thousands of schools, so the disclosure raises concerns about pupil and staff data security.
- 2Harvard Business School VPN Now Supports Single Sign-On▼Did You Know? HBS VPN Now Supports Single Sign-On
Harvard Business School has announced that its VPN service now supports Single Sign-On, allowing users to authenticate with their existing HBS credentials instead of separate VPN logins. The update is aimed at simplifying access to campus resources for students, faculty and staff, reducing password fatigue and streamlining the connection process for the school's remote and on-campus community.
- 3New NetScaler Zero-Day Exploited to Disrupt SAML Deployments▼New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Security researchers report a new zero-day vulnerability in Citrix NetScaler appliances that is being exploited in targeted attacks and can take SAML authentication deployments offline. Organizations relying on NetScaler for single sign-on face potential service outages and unauthorized access risks. Administrators are being urged to apply patches and review their appliances for signs of compromise as details of active exploitation emerge.
- 4Citrix NetScaler SAML zero-day actively exploited, added to CISA KEV●🚨 Citrix NetScaler SAML zero-day (CVE-2026-88779, CVSS 8.7) in CISA KEV. Actively exploited. Memory overflow in SAML han
A zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88779 with a CVSS score of 8.7, has been added to CISA's Known Exploited Vulnerabilities catalog amid reports of active exploitation. The flaw is a memory overflow in the SAML handler that can crash the appliance, disrupting VPN and SSO services for organizations using SAML SP or IdP configurations. Researchers warn it may bypass the previous patch. Fixed builds are 14.1-73.41 and 13.1-64.28, and administrators are urged to update immediately.
- 5WorkOS publishes developer guide to SSO●WorkOS https://workos.com/guide/the-developers-guide-to-sso?utm_source=daringfireball&utm_medium=newsletter&utm_campaign
WorkOS has released a developer's guide to single sign-on (SSO), aimed at engineers building authentication into their applications. The guide is being circulated among technology and Apple-focused readers after it was linked from John Gruber's Daring Fireball newsletter, drawing attention to WorkOS's tools for handling enterprise SSO integrations.
- 6New Citrix NetScaler flaw lets attackers crash appliances remotely●Citrix NetScaler has a new unauthenticated flaw (CVE-2026-88779) that lets a stranger crash the appliance. It hits boxes
Citrix NetScaler appliances have a new unauthenticated vulnerability, tracked as CVE-2026-88779, that allows a remote attacker to crash the device. It affects systems configured for SAML single sign-on, a common enterprise gateway setup. No workaround exists, so administrators are urged to update to version 14.1-73.41 immediately. Security professionals are spreading the word to speed up patching.