时间:2025-11-22 04:13:05 来源:网络整理编辑:時尚
Okta, the San Francisco-based identity and access management company, reported a security breach on
Okta, the San Francisco-based identity and access management company, reported a security breach on Friday. Hackers gained access to private customer information through its customer support management system.
In a site-wide announcement, Okta Chief Security Officer David Bradbury revealed that hackers viewed content uploaded by some Okta customers related to recent support cases. These files, known as HTTP archive (HAR) files, help support personnel replicate customer browser activity for troubleshooting.
SEE ALSO:23andMe may have suffered yet another breach – your data is in jeopardy"HAR files can also contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users," Bradbury said.
Bradbury did not disclose how the credentials were stolen nor if two-factor authentication was in place for the compromised support system. To mitigate the damage, Okta revoked embedded session tokens and advised customers to sanitize credentials within HAR files before sharing.
According to Arstechnica, the initial hack was stopped by security firm BeyondTrust, which alerted Okta to suspicious activity about a month ago. However, due to some flaws within Okta's security model, some actions were still carried out by malicious actors.
Bradbury confirmed that all affected customers have been informed. He also provided IP addresses and browser user agents associated with the hackers for further investigation. He also added that Okta's main production service and Auth0/CIC case management system remain unaffected.
Okta has had its fair share of hacker troubles lately. In March 2022, a group called Lapsus$ accessed an Okta admin panel, allowing them to reset customer passwords and authentication credentials. In December of that same year, Okta's source code was stolen from a GitHub account.
TopicsCybersecurity
Aly Raisman catches Simone Biles napping on a plane like a champion2025-11-22 03:48
李鐵好友:鐵子的心大得很 批評質疑這些東西都裝得下2025-11-22 03:22
津門虎戰大連欲打翻身仗 外援中衛卡達爾已結束隔離2025-11-22 03:17
球迷現場突發疾病 熱刺紐卡中斷比賽為生命讓路2025-11-22 02:54
Whyd voice2025-11-22 02:39
C羅僅1射正進攻端碌碌無為 馬奎爾多次失誤釀丟球2025-11-22 02:12
洛國富發文回應球迷鼓勵 :謝謝大家的照顧(圖)2025-11-22 02:10
曝紐卡冬窗預算5000萬鎊 簽大牌球星可追加資金2025-11-22 02:06
Pole vaulter claims his penis is not to blame2025-11-22 02:03
足協杯廣東4隊出征剩獨苗 中超爭冠組一半止步2025-11-22 01:39
17 questions you can answer if you're a good communicator2025-11-22 04:12
曼聯前瞻:紅魔殘陣出擊考驗索帥 C羅或延續火熱狀態2025-11-22 04:09
穆帥:我的工作比阿萊格裏更難 我必須去適應球隊2025-11-22 04:05
西媒:沙特財團不僅有意收購國米 還想收購馬賽2025-11-22 03:30
This app is giving streaming TV news a second try2025-11-22 03:17
伊卡爾迪被曝出軌阿根廷女演員 旺達取關並怒斥2025-11-22 03:13
17日賠率:拜仁客勝順利登頂 尤文需防羅馬偷分2025-11-22 02:23
朱廣滬孫雯克瑞斯當“監考” 中國女足新帥本月產生2025-11-22 02:21
Michael Phelps says goodbye to the pool with Olympic gold2025-11-22 02:06
女足帥位6名候選人開始麵試 陳婉婷呼聲很高肇俊哲最被看好2025-11-22 01:29