← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Securing Single Sign-On Against Credential Attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • SSO convenience can concentrate security risks.
  • The 2025 University of Pennsylvania breach involved a compromised SSO account.
  • NIST recommends strong password policies, including length and blocklist checks.
  • Mandatory complexity and routine resets can weaken password security.

SSO: Convenience vs. Concentrated Risk

Single Sign-On (SSO) simplifies user access by allowing a single set of credentials for multiple systems. This convenience, however, can also concentrate security risks. If a single SSO login is compromised, it can grant attackers access to numerous interconnected systems and sensitive data.

Real-World Impact of Compromised SSO

The 2025 University of Pennsylvania breach serves as a notable example. Attackers compromised a PennKey SSO account, subsequently gaining access to internal systems such as VPN, Salesforce, Qlik, SAP, and SharePoint. This incident resulted in the theft of data belonging to 1.2 million individuals, highlighting the severe consequences of an inadequately secured SSO.

Strengthening SSO with Password Policies

To counter these risks, organizations must treat SSO as a critical security control. Implementing strong password policies is fundamental. The latest NIST guidance emphasizes password length and usability, recommending at least 15 characters for single-factor passwords and a minimum of eight characters for passwords used with MFA, allowing up to 64 characters. NIST also advises checking new passwords against blocklists of commonly used or compromised credentials.

Avoiding Counterproductive Password Rules

NIST also recommends against legacy password rules that can inadvertently weaken security. Mandatory complexity requirements and routine password resets often lead users to create predictable patterns, such as minor modifications to existing passwords, making them easier for attackers to guess or crack. Verizon's Data Breach Investigation Report indicates that stolen credentials are a factor in 44.7% of breaches, underscoring the importance of effective password management.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Single Sign-On (SSO) systems, while convenient, concentrate risk, as demonstrated by the 2025 University of Pennsylvania breach where a compromised SSO account led to data theft. Organizations must secure SSO by implementing strong password policies and multi-factor authentication to mitigate these risks. This matters because proper SSO security is crucial for protecting multiple systems and user data from credential-based attacks.