Security teams are increasingly highlighting that strong authentication does not guarantee secure SaaS access once a user is logged in. Research on SaaS session integrity warns that organizations may overestimate the protection provided by phishing-resistant MFA (e.g., FIDO2), device trust, and IdP controls (e.g., Okta, Microsoft Entra ID, Ping), because these measures primarily secure the login event while leaving downstream SSO/session handoffs and post-auth access paths exposed to abuse.
Separately, renewed attention is being drawn to open redirect weaknesses as a practical enabler for phishing and OAuth token theft when redirect URLs are insufficiently constrained. SANS ISC reported a recent increase in scanning for common redirect endpoints (e.g., /continue?url=..., /redirect?url=..., /away?url=..., /goto?url=..., /jump?url=...), with much of the observed activity attributed to 89.248.168.239 in AS202425 (IP Volume), a network described as associated with “bulletproof” hosting; blocking or monitoring this ASN was suggested as a defensive measure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Canary described how information-stealer malware can exfiltrate browser session cookies from SaaS applications and let attackers replay authenticated sessions, bypassing MFA, device trust, and IdP-based controls. The article framed this as a broader architectural gap in HTTP and federation-based SSO rather than a single-vendor issue.
The SANS ISC diary said the observed scanning traffic largely originated from IP address 89.248.168.239, associated with AS202425 (IP Volume). The write-up characterized IP Volume as a bulletproof hoster and suggested defenders may want to block the ASN.
SANS ISC reported that its honeypots recently observed an increase in scanning activity targeting common open-redirect parameters such as /continue?url=, /redirect?url=, /away?url=, /goto?url=, and /jump?url=. The activity suggested active reconnaissance for exploitable open redirect flaws.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.