Okta is once again in trouble as the company's GitHub repositories have been hacked. There does not appear to be any impact to Okta clients, but the service source code appears to have been stolen in the breach.
Okta Support System Compromised by Cookie Hijacking, Security Breach May Have Exposed Customer Files
Attackers were able to steal a session cookie from the Okta support system and access an administrator account, possibly providing them with further access to customer environments in an early October security breach.
Vishing attacks targeting identity management platform Okta have compromised corporate data aggregator CrunchBase, streaming website SoundCloud, and fintech robo-advisor Betterment.
Okta has warned about social engineering attacks by sophisticated actors targeting super administrators by tricking service desk staff into resetting multi-factor authentication for privileged users.
According to cyber security firm Check Point Software Technologies, Android app makers are still not patching old security flaws, some of which date back to 2014.
Olympus suffered a second cyber attack on their Americas operation a month after a suspected ransomware incident shut down its EMEA networks. The cyber attack affected the U.S., Canada, and Latin America.
Japanese tech giant Olympus suffered a suspected BlackMatter ransomware attack in early August that disrupted operations in its European, Middle East, and African operations.
Info stealers are increasingly finding their way into corporate environments, possibly as a result of increased blurring of personal and work devices. Report finds that some 400,000 employee logins are available for sale on dark web sites and illicit Telegram channels.
DICOM medical records systems that are commonly used to store sensitive images were found to expose billion of medical records just by scanning the server IP addresses and known ports.
The latest Gone Phishin' event, finds that about 20% of the subjects were compromised by a simulated phishing email; almost 15% did not recognize a malicious download site. Larger organizations, or those that would be expected to have more robust security training programs, tended to fare the worst.










