Matthias Kaiser

@matthiaskaiser.bsky.social

Vulnerability Researcher. 0xACED. Ex-Apple. Posts are my own.

After many hours of development my Smalidea fork supports: - parameters and variables with type information - conditional breakpoints - change parameters and variables via "expression" or "setValue". Quite happy with the results 😀

Bild

If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292). github.blog/security/sig...

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials

Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

github.blog