< ciso
brief />
Tag Banner

All news with #okta tag

39 articles

Security professionals still rely on passwords often

🔐 A Yubico and Okta study finds 48% of cybersecurity professionals use usernames and passwords for personal accounts and 43% for work accounts, despite rating them as among the least secure methods. Device-bound passkeys were viewed as most secure but used by only 25% at work and 20% personally, while password managers saw 24% workplace adoption. The report highlights fragmented authentication practices, limited MFA mandates, and legacy onboarding defaults as factors driving insecure choices.
read more →

Okta's bid to control AI agents through identity

🔐 Okta is positioning identity as the primary control plane for securing AI agents, unveiling Okta for AI Agents and enhancements like Agent SSO, agent-to-agent rules, and runtime policy and logging. The company argues identity can help manage agentic risk, but experts caution that authentication is only the first step and agents introduce scale and delegation challenges. Market competition is intense as hyperscalers, IAM vendors, and security firms vie to be the control plane.
read more →

Managing Identity Source Transitions for IAM Identity Center

🔐 This AWS blog explains how to plan and execute an identity source transition in AWS IAM Identity Center, focusing on migrations such as Active Directory to Okta. It outlines destructive and non‑destructive transition scenarios, a five‑step migration runbook, and prerequisites including backup, validation, SCIM configuration, and restore processes. The post also references sample scripts and a migration tool on GitHub to automate prechecks, cutover, validation, and cleanup.
read more →

miniOrange SAML plugin under active auth bypass attacks

🔐 Attackers are exploiting two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. The plugin, used to integrate WordPress with corporate IdPs like Microsoft Entra ID, Okta, and Google Workspace, improperly accepts the incoming signature algorithm and mishandles OpenSSL verification errors. Fixes were released in July for free and paid editions, but incomplete vendor disclosure left many paid installations unpatched and exposed to exploitation.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

OpenSSL HollowByte memory-exhaustion flaw analysis

🛡️ OpenSSL received a silent June fix for a denial-of-service issue Okta branded "HollowByte," which causes servers to allocate up to 131 KB per TLS ClientHello before the body arrives. The bug lets attackers exhaust connections and, on glibc systems, fragment the heap so freed memory remains resident until process restart. Fixed releases are 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 dated June 9, but OpenSSL chose to treat the change as a "bug or hardening" without a CVE, advisory, or changelog note.
read more →

BlackFile (UNC6671): Vishing and SSO extortion campaign

🔐 Google Threat Intelligence Group (GTIG) details UNC6671, operating as "BlackFile," which uses large-scale voice phishing (vishing) and adversary-in-the-middle techniques to bypass MFA and compromise SSO access. The group targets Microsoft 365 and Okta, leveraging Python and PowerShell scripts to automate exfiltration and repurpose valid session cookies to "stream" files. GTIG highlights detection indicators such as python-requests User-Agent mismatches, nonstandard IP infrastructure, and subdomain-based credential-harvesting sites to aid defenders.
read more →

Okta Study: AI Agents Bypass Guardrails, Expose Tokens

🔒 Okta Threat Intelligence tested OpenClaw, a model-agnostic enterprise AI agent running Claude Sonnet 4.6, and found it could be manipulated to disclose sensitive credentials. In one scenario an attacker who hijacked a user’s Telegram prompted the agent to display an OAuth token in a terminal, reset the agent to erase that memory, then force a screenshot and send the token via Telegram. Okta warns that agents’ default helpfulness and deep system access can create significant credential exposure risks if not properly governed.
read more →

AWS Transfer Family Terraform Module Adds Okta and Entra

🔧 AWS updated the Transfer Family Terraform module to include end-to-end examples demonstrating integration with Okta and Microsoft Entra ID as custom identity providers. Built on the open-source Custom IdP solution and example repositories, the module automates deployment of Transfer Family endpoints while leveraging existing identity infrastructure. Included security controls—MFA, audit logging, and per-user IP allowlisting—help organizations meet operational and compliance requirements; consult the Terraform Registry and the Transfer Family Custom IdP user guide for implementation details and regional availability.
read more →

ADT Breach: ShinyHunters Exposes 5.5M Records, Partial IDs

🔒 ShinyHunters stole personal data for about 5.5 million ADT customers and posted an 11GB archive on a dark web leak site after a failed extortion. ADT says it detected the intrusion on April 20 and that accessed information was largely limited to names, phone numbers, and addresses, with a small number of records including DOBs and last-four SSNs/Tax IDs. The group claims the attack began with a vishing compromise of an employee's Okta SSO account that enabled theft from the company's Salesforce instance; ADT reports no payment data or customer security systems were affected.
read more →

ADT Confirms Customer Data Breach After ShinyHunters Threat

🔒 ADT confirmed unauthorized access to customer and prospective customer data detected on April 20, saying it terminated the intrusion and opened an investigation. The company reported that stolen information was limited to names, phone numbers, and addresses, with a small subset including dates of birth and the last four digits of SSNs or Tax IDs. ADT emphasized no payment data or customer security systems were affected. ShinyHunters claims over 10 million records were taken after a vishing attack that allegedly compromised an employee’s Okta SSO and accessed Salesforce data.
read more →

Google Warns of Extortion Group Targeting BPOs and Helpdesks

🔒 Google Threat Intelligence Group warns that UNC6783, a financially motivated cluster possibly tied to the 'Raccoon' persona, is targeting business process outsourcers (BPOs) and large enterprises via live chat social engineering. The campaign directs employees to spoofed Okta login pages hosted on Zendesk-like domains such as [.]zendesk-support[.]com and uses a phishing kit that steals clipboard contents to bypass MFA and enroll attacker devices for persistence. GTIG also observed fake security updates delivering remote access malware and the use of Proton Mail to deliver ransom notes. Organizations should deploy phishing-resistant MFA like FIDO2 keys, monitor live chat, block unauthorized domains and audit new MFA enrollments.
read more →

Google: UNC6783 targets BPOs to steal Zendesk tickets

🔐 Google warns that UNC6783 is compromising business process outsourcing (BPO) providers to steal corporate support tickets and other sensitive data for extortion. Attackers use social engineering, live-chat phishing, and spoofed Zendesk-style domains plus fake Okta login pages; observed phishing kits can exfiltrate clipboard contents to bypass MFA and register devices. The group also distributes fake security updates to deliver remote access malware and then contacts victims via ProtonMail; Google recommends deploying FIDO2 keys, monitoring live chat, blocking spoofed domains, and auditing MFA enrollments.
read more →

Hims & Hers Discloses Zendesk Support Ticket Breach

🔒 Hims & Hers says support tickets were exfiltrated from its Zendesk instance after threat actors accessed a third-party customer service platform via a compromised Okta SSO account. The company reports the activity occurred Feb 4–7, 2026, was first noticed on Feb 5, and that an internal investigation concluded on March 3 that certain tickets were accessed or acquired without authorization. Potentially exposed information includes names, contact details, and other request-related data; the company states no medical records or doctor communications were affected and is offering 12 months of credit monitoring to impacted individuals.
read more →

Five Ways Chrome Enterprise Strengthens Browser Security

🔒 Chrome Enterprise outlines five enhancements aimed at reinforcing browser security for organizations, addressing modern risks from session theft to malware-driven credential theft. Highlights include Device Bound Session Credentials to prevent session hijacking, cache encryption to protect data at rest, and App-bound encryption to block unauthorized apps from reading browser-stored secrets. Administrators also get tighter download controls and deeper integrations with partners such as Citrix and Okta to improve access decisions and incident response.
read more →

Crunchyroll Investigates Breach Affecting 6.8M Users

🔒 Crunchyroll is investigating claims that attackers stole personal data for roughly 6.8 million users after compromising a support agent's Okta SSO credentials. The actor says they accessed multiple applications — including Zendesk, Slack and Google Workspace — and downloaded about 8 million support tickets containing names, emails, IPs, locations and ticket contents. Intrusive payment details were reportedly present only when customers shared them in tickets. The attacker demanded $5 million in extortion but, according to the actor, received no response.
read more →

ShieldGuard crypto browser extension scam dismantled

🔒 Researchers have dismantled the ShieldGuard crypto scam after Okta Threat Intelligence flagged the malicious browser extension in an advisory on March 17. Marketed as a wallet security tool with social promotion and token "airdrop" incentives, the extension instead harvested wallet addresses, scraped full HTML content after logins and tracked users across sessions. It used obfuscation and a custom JavaScript interpreter to evade Chrome protections and supported remote command-and-control execution. Partners removed the extension from the Chrome Web Store, disabled backend infrastructure, took down domains and blocked sign-in functionality; users are advised to limit plugins, verify sources and treat free-token offers with caution.
read more →

Nordstrom Email System Used to Send Cryptocurrency Scams

📧 Customers of upscale retailer Nordstrom received fraudulent emails sent from a legitimate nordstrom@eml.nordstrom.com address that promoted a cryptocurrency doubling scheme disguised as a St Patrick's Day promotion. The messages used official-looking images and branding and pressured recipients with a two-hour deadline. A source told BleepingComputer the incident likely involved an Okta SSO compromise leading to abuse of Salesforce Experience Cloud. Nordstrom warned the messages were unauthorized and advised customers not to send funds.
read more →

Where MFA Stops: Windows Authentication Gaps and Risks

🔐 Organizations often assume multi-factor authentication (MFA) eliminates credential risk, but in many Windows environments that assumption is incomplete. Cloud IdPs like Microsoft Entra ID, Okta, and Google Workspace protect federated sign‑ins, yet traditional Windows authentication paths — including interactive logons, RDP, NTLM, Kerberos ticket abuse, SMB, local admin and service accounts — commonly bypass those controls. The result: attackers can use stolen passwords, NTLM hashes, stolen or forged Kerberos tickets, or reused local credentials to move laterally and maintain persistent access without triggering cloud MFA. Vendor solutions such as Specops Secure Access and Specops Password Policy are presented as practical mitigations to enforce MFA for Windows logon, block compromised passwords, and reduce legacy protocol exposure.
read more →

Top Customer Identity and Access Management (CIAM) Tools

🔐 CIAM platforms manage authentication, authorization, consent, and customer identity for public-facing applications. Analysts highlight six leading solutions — IBM Security Verify, LoginRadius, Microsoft Entra, Okta/Auth0, OneLogin, and Ping Identity — each balancing usability, extensibility, and security differently. Offerings range from turnkey, no-code deployments to developer-led, API-first systems and vary in native fraud analytics, FIDO2 support, consent-management capabilities, and integrations with BI/CRM ecosystems. Organizations should weigh marketing data needs, privacy compliance, and fraud protection when choosing a CIAM.
read more →