I put in the URL /news as a page all users have access to after login. I just ended up at the login page again and I can see the redirect URL, after login, will be /news
/login/?redirect_to&redirect_to=https%3A%2F%2Fsitedomain.com%2Fnews%2F%3Flogged_in_as_user%3Dtrue&aiowps_login_msg_id=session_expired
That additional querystring param of aiowps_login_msg_id session_expired belongs to ‘All in one WP security’, could that be culprit?