时间:2026-01-06 19:57:08 来源:网络整理编辑:時尚
Okta, the San Francisco-based identity and access management company, reported a security breach on
Okta, the San Francisco-based identity and access management company, reported a security breach on Friday. Hackers gained access to private customer information through its customer support management system.
In a site-wide announcement, Okta Chief Security Officer David Bradbury revealed that hackers viewed content uploaded by some Okta customers related to recent support cases. These files, known as HTTP archive (HAR) files, help support personnel replicate customer browser activity for troubleshooting.
SEE ALSO:23andMe may have suffered yet another breach – your data is in jeopardy"HAR files can also contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users," Bradbury said.
Bradbury did not disclose how the credentials were stolen nor if two-factor authentication was in place for the compromised support system. To mitigate the damage, Okta revoked embedded session tokens and advised customers to sanitize credentials within HAR files before sharing.
According to Arstechnica, the initial hack was stopped by security firm BeyondTrust, which alerted Okta to suspicious activity about a month ago. However, due to some flaws within Okta's security model, some actions were still carried out by malicious actors.
Bradbury confirmed that all affected customers have been informed. He also provided IP addresses and browser user agents associated with the hackers for further investigation. He also added that Okta's main production service and Auth0/CIC case management system remain unaffected.
Okta has had its fair share of hacker troubles lately. In March 2022, a group called Lapsus$ accessed an Okta admin panel, allowing them to reset customer passwords and authentication credentials. In December of that same year, Okta's source code was stolen from a GitHub account.
TopicsCybersecurity
Daughter gives her 1002026-01-06 19:39
周雲妻子評蘇寧欠薪:大家拚命陪你度過難關 你卻視而不見2026-01-06 19:36
反轉 ?曝巴黎主席告知其它球隊 姆巴佩已完成續約2026-01-06 19:33
記者 :中超模式是8+8+8+10 後麵考慮恢複主客場製2026-01-06 19:14
Man stumbles upon his phone background in real life2026-01-06 18:59
國安一線隊啟程奔赴梅州賽區 郭全博+新援田玉達暫未隨隊2026-01-06 18:47
明牌 !安切洛蒂:歐冠決賽踢433 羅德裏戈會出場2026-01-06 18:39
西甲資訊:皇馬進入歐冠決賽 巴薩鎖定歐冠席位2026-01-06 18:35
Here's what 'Game of Thrones' actors get up to between takes2026-01-06 18:09
FIFA官方:2023年女足世界杯抽簽將於10月22日進行2026-01-06 17:20
This 'sh*tpost' bot makes terrible memes so you don't have to2026-01-06 19:54
曝姆巴佩在馬德裏和皇馬代表用餐 商討加盟事宜2026-01-06 19:43
媒體人 :海口最有可能成第三個賽區 中超能6月初開賽就不錯2026-01-06 19:31
前蘇寧球員集體討薪:恭喜國米和張總 欠薪已經拖一年多了2026-01-06 19:30
Researchers create temporary tattoos you can use to control your devices2026-01-06 19:17
連媒:河北隊是頭號降級熱門 金鍾夫堅守令人欽佩2026-01-06 19:09
韓媒 :中超要在世界杯開賽前踢完? 中國球迷表達了不同意見2026-01-06 19:03
官方 :多特宣布今夏第4簽 3000萬敲定哈蘭德替身2026-01-06 17:52
Fyvush Finkel, Emmy winner for 'Picket Fences,' dies at 932026-01-06 17:52
西班牙人官方:球隊主帥莫雷諾下課 體育總監離職2026-01-06 17:14