JWT Puzzles – A Unique Large-Scale Application Attack for Red Teams engagements

No ratings

Presented at DeepSec 2025 by

This talk unveils 'JWT Puzzles,' a novel and systemic application attack enabling significant lateral movement and privilege escalation within enterprise environments. We expose how common organizational misconfigurations—including shared signing keys and insufficient validation across multiple web applications—create a critical, often overlooked attack surface. Attendees will witness practical demonstrations of how seemingly isolated JWT vulnerabilities can be "mixed and matched" to compromise entire interconnected networks