Monday, December 4, 2023
No Result
View All Result
AI CRYPTO BUZZ
  • Home
  • Bitcoins
  • Crypto
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • NFT
  • Blockchain
  • AI
  • ML
  • Cyber Security
  • Web3
  • Metaverse
  • DeFi
  • Analysis
Marketcap
  • Home
  • Bitcoins
  • Crypto
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • NFT
  • Blockchain
  • AI
  • ML
  • Cyber Security
  • Web3
  • Metaverse
  • DeFi
  • Analysis
Marketcap
No Result
View All Result
AI CRYPTO BUZZ
No Result
View All Result

Okta’s Latest Security Breach Is Haunted by the Ghost of Incidents Past

October 26, 2023
in Cyber Security
Reading Time: 2 mins read
0 0
A A
0
Home Cyber Security
Share on FacebookShare on Twitter


“That is the second time Cloudflare has been impacted by a breach of Okta’s methods,” a gaggle of Cloudflare engineers wrote on Friday. They went on to share an inventory of suggestions for the way Okta can enhance its safety posture: “Take any report of compromise critically and act instantly to restrict injury. Present well timed, accountable disclosures to your clients once you determine {that a} breach of your methods has affected them. Require {hardware} keys to guard all methods, together with third-party assist suppliers.”

The Cloudflare engineers added that they view taking protecting steps like these as “desk stakes” for an organization like Okta that gives such essential safety companies to so many organizations.

When WIRED requested Okta a collection of questions on what steps it’s taking to enhance customer support defenses within the wake of the 2 breaches, and why there seems to be a scarcity of urgency when the corporate receives stories of potential incidents, the corporate declined to remark. A spokesperson mentioned it could share extra details about these topics quickly.

“I actually wish to know what technical controls Okta had applied following the 2022 breach, and why this time might be totally different,” says Evan Johnson, cofounder of RunReveal, which develops a system visibility and incident detection device. “My hunch is they didn’t roll out {hardware} safety keys, or didn’t roll them out for his or her contractors doing assist.”

Jake Williams, a former US Nationwide Safety Company hacker and present college member on the Institute for Utilized Community Safety, emphasizes that “the difficulty is greater than Okta,” noting that software program provide chain assaults and the amount of hacks corporations should defend towards is critical. “It is sadly frequent for service suppliers of any measurement to have bother believing they’re the supply of an incident till definitive proof is obtainable,” he says.

Nonetheless, Williams provides, “there is a sample right here with Okta, and it entails outsourced assist.” He additionally notes that one of many remediations Okta steered to clients within the wake of the current incident—rigorously eradicating assist session tokens that could possibly be compromised from troubleshooting information—just isn’t real looking.

“Okta’s suggestion—that one way or the other the client have to be answerable for stripping session tokens from the recordsdata they particularly request for troubleshooting functions—is absurd,” he says. “That is like handing a knife to a toddler after which blaming the toddler for bleeding.”



Source link

Tags: BreachGhostHauntedIncidentsLatestOktasSecurity
Previous Post

Sam Bankman-Fried to Testify in His Defense

Next Post

Grammar checking at Google Search scale – Google Research Blog

Related Posts

Inside America’s School Internet Censorship Machine
Cyber Security

Inside America’s School Internet Censorship Machine

December 4, 2023
ChatGPT Spit Out Sensitive Data When Told to Repeat ‘Poem’ Forever
Cyber Security

ChatGPT Spit Out Sensitive Data When Told to Repeat ‘Poem’ Forever

December 3, 2023
When It Comes to January 6 Lawsuits, a Court Splits Donald Trump in Two
Cyber Security

When It Comes to January 6 Lawsuits, a Court Splits Donald Trump in Two

December 2, 2023
Anduril’s New Drone Killer Is Locked on to AI-Powered Warfare
Cyber Security

Anduril’s New Drone Killer Is Locked on to AI-Powered Warfare

December 1, 2023
Use CodeWhisperer to identify issues and use suggestions to improve code security in your IDE
Cyber Security

Use CodeWhisperer to identify issues and use suggestions to improve code security in your IDE

December 1, 2023
How to improve cross-account access for SaaS applications accessing customer accounts
Cyber Security

How to improve cross-account access for SaaS applications accessing customer accounts

November 30, 2023
Next Post
Grammar checking at Google Search scale – Google Research Blog

Grammar checking at Google Search scale – Google Research Blog

Will Ethereum Rally Continue? These Could Be The Factors To Watch

Will Ethereum Rally Continue? These Could Be The Factors To Watch

Synthetix V3 Pools: A Comprehensive Guide

Synthetix V3 Pools: A Comprehensive Guide

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Facebook Twitter Instagram Youtube RSS
AI CRYPTO BUZZ

The latest news and updates about the Cryptocurrency and AI Technology around the world... The AI Crypto Buzz keeps you in the loop.

CATEGORIES

  • Altcoins
  • Analysis
  • Artificial Intelligence
  • Bitcoins
  • Blockchain
  • Crypto Exchanges
  • Cyber Security
  • DeFi
  • Ethereum
  • Machine Learning
  • Metaverse
  • NFT
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 AI Crypto Buzz.
AI Crypto Buzz is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoins
  • Crypto
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • NFT
  • Blockchain
  • AI
  • ML
  • Cyber Security
  • Web3
  • Metaverse
  • DeFi
  • Analysis

Copyright © 2023 AI Crypto Buzz.
AI Crypto Buzz is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In