Tag: okta

Okta Warns of Credential Stuffing Attacks Targeting Customer Identity Cloud
News

Okta Warns of Credential Stuffing Attacks Targeting Customer Identity Cloud

Okta is alerting users to the possibility of credential stuffing attacks, which are masterminded by threat actors, against a cross-origin authentication functionality in Customer Identity Cloud (CIC). The Identity and access management (IAM) services provider stated, "We observed that the endpoints used to support the cross-origin authentication feature were being attacked via credential stuffing for a number of our customers." Commencing on April 15, 2024, the corporation reported that it "proactively" notified clients who had enabled the function of the questionable activities. The number of clients affected by the attacks was not disclosed. Credential stuffing is a cyberattack tactic when attackers try to log in to online services using a list of usernames and passwords read m...
Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks
News

Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks

The provider of identity and access management (IAM) services Okta has issued a warning over an increase in the "frequency and scale" of assaults known as credential stuffing that target online services. The company stated in an alert released on Saturday that "the broad availability of residential proxy services, lists of previously stolen credentials ('combo lists'), and scripting tools" are what are allegedly facilitating these unprecedented attacks, which have been noticed over the last month. The results expand upon a recent Cisco advice that warned of a global upsurge in brute-force assaults targeting several devices, including web application authentication interfaces, Virtual Private Network (VPN) services, and SSH services, since at least March 18, 2024. Talos said at th...
1Password Detects Suspicious Activity Following Okta Support Breach
News

1Password Detects Suspicious Activity Following Okta Support Breach

well-liked password organizer After the support system compromise, 1Password reported that it saw suspicious activity on its Okta instance on September 29. However, it emphasized that no user data was taken. Pedro Canahuati, CTO of 1Password, stated in a notice on Monday, "We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing." After an IT team member shared a HAR file with Okta Support, the breach is believed to have happened via a session cookie, and the threat actor carried out the following series of actions: attempted to access the user dashboard of the IT team member, however Okta stopped it updated a pre-existing IDP connected to our output Google surroundings Enab...
Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges
News

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges

On Friday, Okta, a provider of identity services, issued a warning about social engineering assaults planned by threat actors to gain elevated administrator permissions. The caller's tactic, according to the company, was to persuade service desk staff to reset all multi-factor authentication (MFA) factors enrolled by highly privileged users. "In recent weeks, multiple U.S.-based Okta customers have reported a consistent pattern of social engineering attacks against IT service desk personnel," the company said. The adversary subsequently made the decision to mimic users within the infiltrated organization by abusing the extremely powerful Okta Super Administrator accounts read more Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges. Stay informed wit...
Hackers Breach Okta’s GitHub Repositories, Steal Source Code
Business, Risk, Security

Hackers Breach Okta’s GitHub Repositories, Steal Source Code

The identity and access management service provider Okta said on Wednesday that several of its source code repositories had been improperly accessed earlier this month. According to the firm, "There is no impact to any clients, including any HIPAA, FedRAMP, or DoD customers." Customers are not compelled to take any action. Unknown threat actors gained access to the code repositories for the Okta Workforce Identity Cloud (WIC), which are housed on GitHub, according to the security incident, which was initially reported by Bleeping Computer. The source code was subsequently copied by abusing the access read the complete article Hackers Breach Okta's GitHub Repositories, Steal Source Code.