There's a lot of FUD here, starting with SAML being new. SAML 1.0 was ratified in 2002, and SAML 2.0 was ratified in 2005. Compare that to OAuth, with version 1.0 published by IETF in 2010 and version 2.0 in 2012. Likewise, there are multiple, mature SAML implementations including the open source Shibboleth project, which started in 2000, and SimpleSAMLphp, which started in 2007. I consider Shibboleth the gold standard, against which I measure all SAML implementations.
In just the global research and higher educational community (eduGAIN), there are currently 2588 SAML identity providers and 1792 SAML service providers.
> Now, this [golden SAML] attack isn't real practical as it requires things like the "token-signing private key".
It isn't a flaw in the SAML protocol. If an attacker compromises your IAM infrastructure, be that a domain controller, directory server, KDC, IdP, or OP, they can impersonate your users.