🔶 The Danger of Multi-SSO AWS Cognito User Pools
This post explores security anti-patterns in multi-SSO AWS Cognito User Pools: ghost identity injection via misconfigured Lambda triggers, "triggerSource" blind spots, sub-splitting attacks on "event.userName", and IdP identifier hijacks. It also introduces "maSSO", a weaponized OIDC/SAML IdP for pentesting.
https://blog.doyensec.com/2026/05/05/cloudsectidbits-masso-cognito-sso.html
#aws
Post #1429
454

- ❤ 1
- 👍 1
- 🔥 1