时间:2026-08-21 11:13:52 来源:网络整理编辑:時尚
Okta, the San Francisco-based identity and access management company, reported a security breach on
Okta, the San Francisco-based identity and access management company, reported a security breach on Friday. Hackers gained access to private customer information through its customer support management system.
In a site-wide announcement, Okta Chief Security Officer David Bradbury revealed that hackers viewed content uploaded by some Okta customers related to recent support cases. These files, known as HTTP archive (HAR) files, help support personnel replicate customer browser activity for troubleshooting.
SEE ALSO:23andMe may have suffered yet another breach – your data is in jeopardy"HAR files can also contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users," Bradbury said.
Bradbury did not disclose how the credentials were stolen nor if two-factor authentication was in place for the compromised support system. To mitigate the damage, Okta revoked embedded session tokens and advised customers to sanitize credentials within HAR files before sharing.
According to Arstechnica, the initial hack was stopped by security firm BeyondTrust, which alerted Okta to suspicious activity about a month ago. However, due to some flaws within Okta's security model, some actions were still carried out by malicious actors.
Bradbury confirmed that all affected customers have been informed. He also provided IP addresses and browser user agents associated with the hackers for further investigation. He also added that Okta's main production service and Auth0/CIC case management system remain unaffected.
Okta has had its fair share of hacker troubles lately. In March 2022, a group called Lapsus$ accessed an Okta admin panel, allowing them to reset customer passwords and authentication credentials. In December of that same year, Okta's source code was stolen from a GitHub account.
TopicsCybersecurity
Cat gets stuck in the most awkward position ever2026-08-21 11:09
啥邏輯?皇馬抱怨補時少 裁判:在乎這1分鍾嗎 ?2026-08-21 10:51
哈維踐行巴薩條款正當其時? 接手條件均已滿足2026-08-21 10:44
南美足聯 :拒絕2年1屆世界杯 旗下足協也不會參加2026-08-21 10:43
Ivanka Trump's unpaid interns share cringeworthy financial advice2026-08-21 09:51
馬德興 :國足12強賽主場仍在確認中 足協做好兩手準備2026-08-21 09:09
女足亞洲杯解簽:中國隊小組鶴立雞群 進四強難度不大2026-08-21 09:02
記者:浙江隊11月3日與國足進行熱身賽 6日再與U22國足熱身2026-08-21 08:54
PlayStation Now game streaming is coming to PC2026-08-21 08:46
大哥風範 !曝C羅試圖團結更衣室 呼籲球員支持索帥2026-08-21 08:44
Dramatic photo captures nun texting friends after Italy earthquake2026-08-21 11:05
京媒:女足“躺著”也能進世界杯 能否如期在印度舉辦存疑2026-08-21 10:43
南美足聯:拒絕2年1屆世界杯 旗下足協也不會參加2026-08-21 10:09
中超壓縮賽程有多套預案 最大限度保障國腳多的俱樂部2026-08-21 10:02
Twitter grants everyone access to quality filter for tweet notifications2026-08-21 10:01
索帥生死戰變陣C羅將踢左邊鋒 需要兼顧邊路防守2026-08-21 09:54
How to watch UFC 297 livestreams: schedule, streaming deals, and more2026-08-21 09:47
啥邏輯 ?皇馬抱怨補時少 裁判 :在乎這1分鍾嗎?2026-08-21 09:31
U.S. government issues warning on McDonald's recalled wearable devices2026-08-21 09:19
記者 :博格巴上場前還被提醒別做蠢事 比如被罰下2026-08-21 08:51