SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
Insights
Engineering perspectives on architecture, product development, AI, and the everyday decisions behind useful software.
From the engineering desk
Browse practical articles or follow the latest technology updates.
Subscribe via RSS →Curated links from external sources — not 360Softy original articles.
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
We have deployed a proactive security update to the , protecting against a recently disclosed vulnerability in the package, dubbed SAMLStorm ( and ). This vulnerability, which affects various SAML implementations, could allow attackers to bypass authentication mechanisms.Vercel Firewallxml-cryptoCVE-2025-29774CVE-2025-29775 See the for more details on the vulnerability, and reach out to if you have questions.SAMLStorm reportVercel Support Read more What This Means for Vercel Customers : Verc
now has an for tools to integrate AI models and services directly into Vercel projects.The Vercel MarketplaceAI category Groq, fal, and DeepInfra are available as first-party integrations, allowing users to: With prepaid plan options, users can now manage AI costs more predictably by purchasing credits upfront from a model provider. These credits can be used across any model offered by that provider. Explore the new , , and get started with , , and on the Vercel Marketplace, available to users
A conversation with Minna Song, CEO & Co-founder of EliseAI.
agents-sdk -> agents Updated 📝 We've renamed the Agents package to agents! If you've already been building with the Agents SDK, you can update your dependencies to use the new package name, and replace references to agents-sdk with agents: # Install the new package npm i agents # Remove the old (deprecated) package npm uninstall agents-sdk # Find instances of the old package name in your codebase grep -r 'agents-sdk' . # Replace instances of the old package name with the new one
Now, API Shield automatically labels your API inventory with API-specific risks so that you can track and manage risks to your APIs. View these risks in Endpoint Management by label: ...or in Security Center Insights: API Shield will scan for risks on your API inventory daily. Here are the new risks we're scanning for and automatically labelling: cf-risk-sensitive: applied if the customer is subscribed to the sensitive data detection ruleset and the WAF detects sensitive data returned on an en
Radar has expanded its security insights, providing visibility into aggregate trends in authentication requests, including the detection of leaked credentials through leaked credentials detection scans. We have now introduced the following endpoints: /leaked_credential_checks/summary/{dimension}: Retrieves summaries of HTTP authentication requests distribution across two different dimensions. /leaked_credential_checks/timeseries_groups/{dimension}: Retrieves timeseries data for HTTP authenticati
Join us as we share our latest releases and how ChatGPT is becoming more interactive, customized to the way your teams work, and agentic.
Let’s start with a conversation
An idea, a challenge, or a system that needs to work better. We’ll help you understand the next step.
Prefer email? [email protected]