Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
Critical Vulnerability in OneLogin AD Connector Enables JWT Forgery and Cross-Tenant Account Takeovers
Malware and Vulnerabilities
June 13, 2025
specterops
A critical vulnerability in OneLogin’s AD Connector exposed enterprise authentication systems to severe risk. The flaw allowed attackers to obtain credentials, impersonate users, and access sensitive applications by forging JSON Web Tokens (JWTs).
Read More
OneLogin
Active Directory Connector
JWT Forgery
Identity and Access Management
Authentication Bypass
Publisher
Previous
Developers Beware - Sophisticated Phishing Scams Exploi ...
Threat Intel & Info Sharing
Next
Understanding CyberEYE RAT Builder: Capabilities and Im ...
Malware and Vulnerabilities