CuraSec

tag: Single-Sign-On · 1 items

  • Engineer — Learn: Academic research exposing trust hijacking and credential leakage flaws in carrier-based SSO; the finding that 69.4% of MSSO sites expose developer credentials is a useful design caution for any team integrating telecom-backed identity flows, though MSSO is rare in typical US cloud stacks.
  • SOC/IR — Learn: The One-Click-to-Leak attack class (phone number exfiltration via single page visit) is a novel auth-layer technique worth filing for threat modeling, but the paper provides no IOCs, ATT&CK mappings, or detection rules to act on today.
  • Leader — Skip