TGViewer
RedTeam feed RedTeam feed @redteamfeed · 602 subscribers
Post #1660 244
Signature Optional - Analysis of CVE-2026-28323
#bishopfox

SolarWinds Web Help Desk treated SAML signature verification as optional and skipped every other validation the spec requires. Bishop Fox confirmed the full exploit end to end: one forged POST request, no credentials, full session takeover. Here is the root cause, the fix, and how to detect it.

via BishopFox Blog
More from @redteamfeed
  1. Sep 23, 2026HTTP/3 in Burp Suite - it’s time to find a bigger wordlist #portswigger How many bugs have…
  2. Sep 18, 2026From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion #bishopfox Fo…
  3. Sep 17, 2026MikroTrick: Inside the RouterOS Takeover Chain #bishopfox Attackers were exploiting MikroT…
  4. Sep 17, 2026CiliumHound: Graphing Kubernetes Network Policies #specterops TLDR: CiliumHound is a Blood…
  5. Sep 17, 2026Unpacking a laZzzy Donut #trustedsec Recently, we came across an interesting malware sampl…
  6. Sep 16, 2026Ghostwriter v7.3.0: A Fresh New Look #specterops TL;DR: The upcoming Ghostwriter v7.3.0 re…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →