<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — Authentication</title>
  <link>https://appsec.fyi/authn.html</link>
  <description>Curated Authentication resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/authn.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Fri, 10 Apr 2026 21:32:17 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>Semrush OAuth redirect_uri bypass via IDN homograph — HackerOne #861940</title>
    <link>https://hackerone.com/reports/861940</link>
    <guid isPermaLink="true">https://hackerone.com/reports/861940</guid>
    <description>Semrush OAuth redirect_uri bypass via IDN homograph — HackerOne #861940</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:25 +0000</pubDate>
  </item>
  <item>
    <title>Slack OAuth2 redirect_uri bypass — HackerOne #2575</title>
    <link>https://hackerone.com/reports/2575/</link>
    <guid isPermaLink="true">https://hackerone.com/reports/2575/</guid>
    <description>Slack OAuth2 redirect_uri bypass — HackerOne #2575</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:25 +0000</pubDate>
  </item>
  <item>
    <title>Cisco Talos: State-of-the-art phishing — MFA bypass</title>
    <link>https://blog.talosintelligence.com/state-of-the-art-phishing-mfa-bypass/</link>
    <guid isPermaLink="true">https://blog.talosintelligence.com/state-of-the-art-phishing-mfa-bypass/</guid>
    <description>Cisco Talos: State-of-the-art phishing — MFA bypass</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:24 +0000</pubDate>
  </item>
  <item>
    <title>Bugcrowd: How attackers bypass multi-factor authentication (Part 1)</title>
    <link>https://www.bugcrowd.com/blog/mfa-security-part-1-how-attackers-bypass-multi-factor-authentication/</link>
    <guid isPermaLink="true">https://www.bugcrowd.com/blog/mfa-security-part-1-how-attackers-bypass-multi-factor-authentication/</guid>
    <description>Bugcrowd: How attackers bypass multi-factor authentication (Part 1)</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:23 +0000</pubDate>
  </item>
  <item>
    <title>webauthn.me: WebAuthn and Passkeys guide</title>
    <link>https://www.webauthn.me/passkeys</link>
    <guid isPermaLink="true">https://www.webauthn.me/passkeys</guid>
    <description>webauthn.me: WebAuthn and Passkeys guide</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:23 +0000</pubDate>
  </item>
  <item>
    <title>FIDO Alliance: Passkeys overview</title>
    <link>https://fidoalliance.org/passkeys/</link>
    <guid isPermaLink="true">https://fidoalliance.org/passkeys/</guid>
    <description>FIDO Alliance: Passkeys overview</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:22 +0000</pubDate>
  </item>
  <item>
    <title>Hackmanit: XML Signature Validation Bypass in SimpleSAMLphp and xmlseclibs</title>
    <link>https://hackmanit.de/en/blog-en/82-xml-signature-validation-bypass-in-simplesamlphp-and-xmlseclibs/</link>
    <guid isPermaLink="true">https://hackmanit.de/en/blog-en/82-xml-signature-validation-bypass-in-simplesamlphp-and-xmlseclibs/</guid>
    <description>Hackmanit: XML Signature Validation Bypass in SimpleSAMLphp and xmlseclibs</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:21 +0000</pubDate>
  </item>
  <item>
    <title>epi052: How to Hunt Bugs in SAML — A Methodology (Part II)</title>
    <link>https://epi052.gitlab.io/notes-to-self/blog/2019-03-13-how-to-test-saml-a-methodology-part-two/</link>
    <guid isPermaLink="true">https://epi052.gitlab.io/notes-to-self/blog/2019-03-13-how-to-test-saml-a-methodology-part-two/</guid>
    <description>epi052: How to Hunt Bugs in SAML — A Methodology (Part II)</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:20 +0000</pubDate>
  </item>
  <item>
    <title>IBM: What is XML Signature Wrapping?</title>
    <link>https://www.ibm.com/think/topics/xml-signature-wrapping</link>
    <guid isPermaLink="true">https://www.ibm.com/think/topics/xml-signature-wrapping</guid>
    <description>IBM: What is XML Signature Wrapping?</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:20 +0000</pubDate>
  </item>
  <item>
    <title>USENIX: On Breaking SAML — Be Whoever You Want to Be</title>
    <link>https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final91.pdf</link>
    <guid isPermaLink="true">https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final91.pdf</guid>
    <description>USENIX: On Breaking SAML — Be Whoever You Want to Be</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:19 +0000</pubDate>
  </item>
  <item>
    <title>Astrix Security: How attackers exploit OAuth — a deep dive (Part 2)</title>
    <link>https://astrix.security/learn/blog/part-2-how-attackers-exploit-oauth-a-deep-dive/</link>
    <guid isPermaLink="true">https://astrix.security/learn/blog/part-2-how-attackers-exploit-oauth-a-deep-dive/</guid>
    <description>Astrix Security: How attackers exploit OAuth — a deep dive (Part 2)</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:18 +0000</pubDate>
  </item>
  <item>
    <title>The Hacker Recipes: OAuth 2.0</title>
    <link>https://www.thehacker.recipes/web/config/identity-and-access-management/oauth-2.0</link>
    <guid isPermaLink="true">https://www.thehacker.recipes/web/config/identity-and-access-management/oauth-2.0</guid>
    <description>The Hacker Recipes: OAuth 2.0</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:17 +0000</pubDate>
  </item>
  <item>
    <title>Security Innovation: Pentester&#x27;s Guide to Evaluating OAuth 2.0</title>
    <link>https://blog.securityinnovation.com/pentesters-guide-to-evaluating-oauth-2.0</link>
    <guid isPermaLink="true">https://blog.securityinnovation.com/pentesters-guide-to-evaluating-oauth-2.0</guid>
    <description>Security Innovation: Pentester&#x27;s Guide to Evaluating OAuth 2.0</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:17 +0000</pubDate>
  </item>
  <item>
    <title>0xn3va: OAuth 2.0 Vulnerabilities cheat sheet</title>
    <link>https://0xn3va.gitbook.io/cheat-sheets/web-application/oauth-2.0-vulnerabilities</link>
    <guid isPermaLink="true">https://0xn3va.gitbook.io/cheat-sheets/web-application/oauth-2.0-vulnerabilities</guid>
    <description>0xn3va: OAuth 2.0 Vulnerabilities cheat sheet</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:16 +0000</pubDate>
  </item>
  <item>
    <title>Cobalt: OAuth Vulnerabilities Part 2</title>
    <link>https://www.cobalt.io/blog/oauth-vulnerabilites-pt.-2</link>
    <guid isPermaLink="true">https://www.cobalt.io/blog/oauth-vulnerabilites-pt.-2</guid>
    <description>Cobalt: OAuth Vulnerabilities Part 2</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:15 +0000</pubDate>
  </item>
  <item>
    <title>Vaadata: Understanding OAuth 2.0 and its common vulnerabilities</title>
    <link>https://www.vaadata.com/blog/understanding-oauth-2-0-and-its-common-vulnerabilities/</link>
    <guid isPermaLink="true">https://www.vaadata.com/blog/understanding-oauth-2-0-and-its-common-vulnerabilities/</guid>
    <description>Vaadata: Understanding OAuth 2.0 and its common vulnerabilities</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:14 +0000</pubDate>
  </item>
  <item>
    <title>Doyensec: Common OAuth Vulnerabilities</title>
    <link>https://blog.doyensec.com/2025/01/30/oauth-common-vulnerabilities.html</link>
    <guid isPermaLink="true">https://blog.doyensec.com/2025/01/30/oauth-common-vulnerabilities.html</guid>
    <description>Doyensec: Common OAuth Vulnerabilities</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:14 +0000</pubDate>
  </item>
  <item>
    <title>OWASP WSTG: Testing for Session Fixation</title>
    <link>https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/03-Testing_for_Session_Fixation</link>
    <guid isPermaLink="true">https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/03-Testing_for_Session_Fixation</guid>
    <description>OWASP WSTG: Testing for Session Fixation</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:13 +0000</pubDate>
  </item>
  <item>
    <title>OWASP: Session Fixation Protection</title>
    <link>https://owasp.org/www-community/controls/Session_Fixation_Protection</link>
    <guid isPermaLink="true">https://owasp.org/www-community/controls/Session_Fixation_Protection</guid>
    <description>OWASP: Session Fixation Protection</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:12 +0000</pubDate>
  </item>
  <item>
    <title>OWASP: Session fixation attack</title>
    <link>https://owasp.org/www-community/attacks/Session_fixation</link>
    <guid isPermaLink="true">https://owasp.org/www-community/attacks/Session_fixation</guid>
    <description>OWASP: Session fixation attack</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:11 +0000</pubDate>
  </item>
  <item>
    <title>OWASP Top 10 A07: Identification and Authentication Failures</title>
    <link>https://owasp.org/Top10/2021/A07_2021-Identification_and_Authentication_Failures/</link>
    <guid isPermaLink="true">https://owasp.org/Top10/2021/A07_2021-Identification_and_Authentication_Failures/</guid>
    <description>OWASP Top 10 A07: Identification and Authentication Failures</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:11 +0000</pubDate>
  </item>
  <item>
    <title>OWASP Session Management Cheat Sheet</title>
    <link>https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html</link>
    <guid isPermaLink="true">https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html</guid>
    <description>OWASP Session Management Cheat Sheet</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:10 +0000</pubDate>
  </item>
  <item>
    <title>OWASP Authentication Cheat Sheet</title>
    <link>https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html</link>
    <guid isPermaLink="true">https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html</guid>
    <description>OWASP Authentication Cheat Sheet</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:09 +0000</pubDate>
  </item>
  <item>
    <title>The Fragile Lock: Novel Bypasses for SAML Authentication | PortSwigger Research</title>
    <link>https://portswigger.net/research/the-fragile-lock</link>
    <guid isPermaLink="true">https://portswigger.net/research/the-fragile-lock</guid>
    <description>The Fragile Lock: Novel Bypasses for SAML Authentication | PortSwigger Research</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:08 +0000</pubDate>
  </item>
  <item>
    <title>PortSwigger: OAuth 2.0 authentication vulnerabilities</title>
    <link>https://portswigger.net/web-security/oauth</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/oauth</guid>
    <description>PortSwigger: OAuth 2.0 authentication vulnerabilities</description>
    <category>Authentication</category>
    <pubDate>Fri, 10 Apr 2026 21:22:08 +0000</pubDate>
  </item>
</channel>
</rss>