<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Amazon-Cognito on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/amazon-cognito/</link><description>Recent content in Amazon-Cognito on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 15:49:15 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/amazon-cognito/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS Cognito New Lambda Trigger for Federated Sign-In</title><link>https://zxcloudsecurity.co.uk/posts/aws-cognito-lambda-trigger-federated-sign-in/</link><pubDate>Thu, 04 Jun 2026 15:49:15 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-cognito-lambda-trigger-federated-sign-in/</guid><description>AWS adds a new Cognito Lambda trigger enabling custom logic during federated sign-in via SAML, OIDC, and social providers. Here&amp;#39;s what architects need to k</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/blogs/security/customize-federated-sign-in-with-new-amazon-cognito-lambda-trigger/">AWS Security Blog</a></p>
<hr>
<p>AWS has introduced a new Lambda trigger for Amazon Cognito that allows developers to customise the federated sign-in process when users authenticate via external identity providers such as SAML, OIDC, or social logins. This enables teams to intercept and modify authentication flows at key points, such as attribute mapping or access decisions, without altering core Cognito configuration. The feature improves flexibility for organisations with complex identity federation requirements.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review any existing custom authentication workarounds in your Cognito-integrated applications and assess whether this new trigger can consolidate or replace them — pay particular attention to how federated user attributes are mapped and validated, as improper handling here is a common source of privilege misassignment.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/blogs/security/customize-federated-sign-in-with-new-amazon-cognito-lambda-trigger/">Customize federated sign-in with new Amazon Cognito Lambda trigger</a></p>
]]></content:encoded></item></channel></rss>