An update from Okta on its October customer support security breach indicates that the damage is worse than initially expected, with all of the recent users of its Help Center service now being told that the attackers likely stole their uploaded files.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The final report on the Okta security breach indicates that the attackers were able to access HAR files containing session tokens of 134 customers, but it appears they were very selective in which they chose to pursue follow-up attacks on. Only five instances of successful session hijacking were logged.
Okta is once again in trouble as the company's GitHub repositories have been hacked. There does not appear to be any impact to Okta clients, but the service source code appears to have been stolen in the breach.
Okta Support System Compromised by Cookie Hijacking, Security Breach May Have Exposed Customer Files
Attackers were able to steal a session cookie from the Okta support system and access an administrator account, possibly providing them with further access to customer environments in an early October security breach.
Vishing attacks targeting identity management platform Okta have compromised corporate data aggregator CrunchBase, streaming website SoundCloud, and fintech robo-advisor Betterment.
Okta has warned about social engineering attacks by sophisticated actors targeting super administrators by tricking service desk staff into resetting multi-factor authentication for privileged users.
According to cyber security firm Check Point Software Technologies, Android app makers are still not patching old security flaws, some of which date back to 2014.
On February 5, 2021, a hacker gained access to the water treatment system of Oldsmar, Florida, and attempted to increase...
Olympus suffered a second cyber attack on their Americas operation a month after a suspected ransomware incident shut down its EMEA networks. The cyber attack affected the U.S., Canada, and Latin America.
Japanese tech giant Olympus suffered a suspected BlackMatter ransomware attack in early August that disrupted operations in its European, Middle East, and African operations.










