An authentication bypass in a widely-deployed identity provider, and what we learned about session forgery
Discovered during a flagship engagement in Q1. A logic flaw in the session-token signing process allowed an attacker with read access to a single user's cached token to forge valid sessions for arbitrary tenants. Full writeup, PoC, and the detection rule that would have caught us.