SAML
94
MENTIONS
42
EPISODES
35
PODCASTS
Search complete. 94 mentions across 42 episodes found for "SAML".
Sep 15, 2026
#29: What Is a Lead AI Engineer?
A
26:56Andy RahnHOST
Yeah.
C
26:56Charles ThomasGUEST
And the first iteration of the artifact that I built for our CEO for her emails was a full-fledged email management software with like SAML 2.0 integration and like a Kanban board and like all this crazy stuff.
C
27:13Charles ThomasGUEST
And she looked at it and she's like, "I don't know how to use this.
C
27:16Charles ThomasGUEST
This is too complex for me." And I swooped in and I said, "Look, man, this is...
LangChain CEO Harrison Chase on the infrastructure bet he got wrong
P
39:47Paul Klein IVHOST
Like the logged in web is where agentic identity needs to be solved, but there isn't a protocol that we can bolt on top of.
P
39:53Paul Klein IVHOST
There's like SSO and, and SAML and like OAuth that kind of can help here, but it seems like agents are going to try and access services on behalf of people.
P
40:02Paul Klein IVHOST
And maybe, once again, this goes back to how you and I have different views here or different beliefs.
P
40:06Paul Klein IVHOST
Like I might believe that I think my agent should be a delegate of me because I probably have like a limited scope of access.
Why Your Web Firewall Is an Inside Threat
E
6:52Ernie PrescottHOST
Its entire existence is dedicated to verifying who you are.
J
6:55JoséeHOST
And it does that using modern web protocols, right? OIBC, SAMLNL, OAuth 2.0.
J
7:00JoséeHOST
But what do those actually do in plain English? Because we throw around acronyms like OAuth, but architects need to really understand the mechanism.
E
7:07Ernie PrescottHOST
Think of it like a bouncer at a highly secure club.
Mikrotik and Cisco Active Exploits - The 443 Podcast - Episode 387
M
23:09Marc LaliberteHOST
Um, so basically they pointed to their third party marketing email provider, Brevo, as the source of the issue, and Brevo later put out a statement with some additional information on what happened.
M
23:20Marc LaliberteHOST
They said attackers exploited a flaw in how they handle SAML single sign-on to gain access to 138 different accounts, 6 of which were used to send phishing emails, and 43 of which had their contacts harvested out of it.
M
23:35Marc LaliberteHOST
And basically how the attackers got in is they created their own Brevo account and set up single sign-on to a SAML identity provider.
M
23:43Marc LaliberteHOST
They then invited legitimate Brevo users in other accounts into their tenant.
M
23:50Marc LaliberteHOST
If those Brevo users accepted the invite, the, uh, the attacker could use SAML single sign-on from their IDP that they controlled to log in as that other user.
M
24:01Marc LaliberteHOST
Where the issue was is that should have let them log in as that user in their tenant, the attacker's tenant.
M
24:07Marc LaliberteHOST
But due to some scoping issues, it allowed them to log in as that user in any tenant that that user had access to.
14-Sep-2026 GitLab, Microsoft, Chess.com and Citrix Hit by Cyber Threats
S
2:59speaker_0NARRATOR
And finally, for today.
S
3:01speaker_0NARRATOR
Citrix Netscaler ADC and Gateway are facing CVE-2026-19490, a critical SAML authentication bypass scored CVSS 9.3 that can be triggered by a single unauthenticated request.
S
3:16speaker_0NARRATOR
Security researchers say the impact varies by configuration, ranging from a pre-authentication crash to an internal network proxy, and in some cases, root on the appliance if management credentials are exposed.
S
3:30speaker_0NARRATOR
Defenders are being urged to patch to 13.1.63.2.1 or 14.1.73.3.2 or later, or migrate off end-of-life branches and test each affected virtual server separately.
Secure Your Infrastructure Without Service Accounts
J
9:43JoséeHOST
Yeah.
E
9:43Ernie PrescottHOST
It doesn't understand modern OAuth or SAML tokens.
E
9:46Ernie PrescottHOST
It doesn't even know what a web browser is.
E
9:49Ernie PrescottHOST
It is hard-coded into its very binary to demand classic Active Directory schema, LD AP queries to look up user roles, and Kerberos or NTLM for authentication.
12 MINS LATER
E
21:53Ernie PrescottHOST
Which is fantastic for security.
J
21:55JoséeHOST
Mm.
E
21:55Ernie PrescottHOST
But once the cloud identity provider verifies the user, it issues a modern session token like a SAML assertion or an OIDC token back to the gateway, and the legacy application still has no idea what to do with the SAML assertion.
J
22:08JoséeHOST
Right.
The Claude Governance Playbook for Growing Businesses
Z
8:46Zach TerryHOST
It allows for really easy onboarding and offboarding.
Z
8:50Zach TerryHOST
So you can even use single sign-on and SAML or SCIM for automated user provisioning.
Z
8:57Zach TerryHOST
you can just essentially define who in your organization has access to cloud.
Z
9:00Zach TerryHOST
I mean, it's very much like a platform, right? You're adding people to have seats and then you're managing their usage, which is also really important because it gives you the ability to monitor that variable cost, that consumption, that usage across the entire team.
NHI & AI Identity Summit : The Next 24 Months
L
0:41Lalit ChodaHOST
We've got someone who is a CEO at ExoniusX.
L
0:45Lalit ChodaHOST
And then finally, someone that co-founded SAML many years ago.
A
0:50Amir OfekGUEST
Just a small correction.
A
0:51Amir OfekGUEST
I'm just going to duck now.
E
1:13Eve MalerGUEST
I go? Hi, everybody.
E
1:16Eve MalerGUEST
Eve Mailer.
E
1:17Eve MalerGUEST
I guess the bookends of my identity career include helping to create SAML 26 years ago, Like, I want to say I'm sorry, but no.
E
1:27Eve MalerGUEST
And most recently, I was the CTO of ForgeRock, and now I am a strategic advisor at VenFactory.
How to Get Into IAM in 2026 | The Real Career Path, Tools & AI
A
21:44Andrew ChanthaphoneGUEST
To me, it says, if you're new to identity or even you're in the space, the fundamentals is the first part of it that a lot of people don't have is the fundamentals of identity.
A
21:53Andrew ChanthaphoneGUEST
What is the different authorization models out there? What are the different authentication models out there? What, what are, what, what is SSO? What is SAML, right? What is OIDC? To be able to understand the lingo and talk to talk is your first part of it, because then once you understand what the actual join or move reliever or onboarding transfers offboarding process is.
A
22:14Andrew ChanthaphoneGUEST
And to be able to explain to somebody easily, I joke about this, but I always tell my people is explain to you as if you're a two or six grader what this is, right? The better you can do that, the more that you know it in your head.
A
22:26Andrew ChanthaphoneGUEST
And I always tell that to my mentees or people who offer, who pay for my services to get mentored is that's the first thing I do is I have them take the fundamentals.
NHI & AI Identity Summit : Governing AI
D
7:05David GoldschlagPANELIST
And if more agents can authenticate themselves in a standardized way, and the credentials that I need to issue are more standardized credentials, it means it's less work to support a bigger variety of things, okay? So I think that that's really critical.
D
7:20David GoldschlagPANELIST
But I think at the end of the day, this business of converting from one identity to one access credential to different ones, that one, the world's just a messy place, okay, right? And that's just my job, okay, right? And so I think we do need to recognize that even in a world of SAML, okay, for instance, for users, you still need identity systems like ENTRE or OKTO or PING, because they're the ones that manage the policies and the real work, right, of deciding what to do, determining posture and risk, right, making an access decision, issuing a credential, that is still sort of above those standards, okay? So that's how I think about standards.
D
8:03David GoldschlagPANELIST
Yeah, yeah, okay.
N
8:05Niv GoldenbergPANELIST
I want to add to that and I think that the standards are really an alignment in terms of a framework for us as an industry and the way that we need to look and to make decisions.
32 more episodes mention SAML.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.