Why Okta Hack is a Big Deal: What You Need to Know

  Рет қаралды 2,087

Technology Leadership

Technology Leadership

2 жыл бұрын

LAPSUS$, a ransomware gang, announced that they had superuser access to Okta. To prove their unfettered access to Okta’s backend, they published a bunch of screenshots on their Telegram channel. The screenshots show that hackers gained access to Okta.com backend and several SaaS providers, like Jira and Salesforce, that Okta uses to run their services. Let me back up a little bit. Okta is a San Francisco-based identity and access management provider. They offer services like Single Sign-On or SSO and Multi-factor Authentication or MFA to thousands of enterprise customers. They are a leader in Gartner’s Magic Quadrant for IAM with over 30% market share. They compete with the likes of Microsoft, Ping Identity and OneLogin.
Okta is a Federal Risk and Authorization Management Program (FedRAMP) approved identity vendor.
#lapsus #Okta #identity
★★ WHO AM I ★★
bit.ly/3qZsCLm
/ afaqmkhan

Пікірлер: 16
@julianaceansah8316
@julianaceansah8316 Жыл бұрын
Nice concise summary of the incident and your concluding comments on how Okta did not manage this incident in the right way resulting in loss of confidence, huge fall in share price and how Lapsus$ has taunted the company with super user access.
@Melosmom
@Melosmom 2 жыл бұрын
I think the issues we often overlook is is third party engagements....
@technologyleadership3132
@technologyleadership3132 2 жыл бұрын
Indeed. It is the equivalent of using third party open source libraries when building an app. It is safe to assume that some part of your Attack surface is always up for grab.
@technologyleadership3132
@technologyleadership3132 2 жыл бұрын
What's your take on the Okta hack? Let's talk. If you liked the video, hit the Like button Will Smith style ;)
@Melosmom
@Melosmom 2 жыл бұрын
Hahahha will smith style
@skepticalsheep
@skepticalsheep 2 жыл бұрын
are you saying he done good ?
@skepticalsheep
@skepticalsheep 2 жыл бұрын
i get it, its funny but what he did was barbaric .
@technologyleadership3132
@technologyleadership3132 2 жыл бұрын
There is some prior history among them. But based on the actual footage, IMO both crossed the line. We all saw a “joke”, but the husband (Will) saw pain on wife’s face who was trying to hold back tears. None justifies an assault.
@skepticalsheep
@skepticalsheep 2 жыл бұрын
@@technologyleadership3132 I believe wise people don't act on emotions.
@skepticalsheep
@skepticalsheep 2 жыл бұрын
Hi Afagh. what Okta should have done to prevent this hack on their 3rd party contracts?
@technologyleadership3132
@technologyleadership3132 2 жыл бұрын
No matter what you do, virtually there is no prevention. There will always be some unmanaged attack surface out there. It is a tall order. Okta could have done the following: 1. Use External Attack Surface Management (EASM) solution (e.g. Cyberpion) 2. As you alluded to, the contract should include cyber incident response. It won't stop attacks but it does help to have a clear well-documented process if and when a third party is compromised. It is just getting started, there will be a lot more collateral damage. Identity management cannot work without Trust. www.wired.com/story/lapsus-okta-hack-sitel-leak/
@skepticalsheep
@skepticalsheep 2 жыл бұрын
@@technologyleadership3132 never heard about EASM, interesting.
@Dr.Octogon
@Dr.Octogon Жыл бұрын
@@technologyleadership3132 That particular technology would not have been effective here and there are a few points in this video that was not accurate.
@billytheweasel
@billytheweasel Жыл бұрын
Ugh, my IRA account requires Okta or Google Authenticator. Is Google Authenticator trustworthy? (checking your vids now, lol)
@winiikumari4411
@winiikumari4411 10 ай бұрын
Okta are real platform?
Zero Trust Security Model Explained
7:48
Technology Leadership
Рет қаралды 309
Okta CEO on Lapsus$: Our Brand Has Been Damaged
9:35
Bloomberg Technology
Рет қаралды 10 М.
- А что в креме? - Это кАкАооо! #КондитерДети
00:24
Телеканал ПЯТНИЦА
Рет қаралды 7 МЛН
Now THIS is entertainment! 🤣
00:59
America's Got Talent
Рет қаралды 38 МЛН
Is Multicloud Networking Market a Hype: What You Need to Know
8:50
Technology Leadership
Рет қаралды 343
The Holy Grail of Spyware: The Pegasus and NSO Group Explained
9:16
Technology Leadership
Рет қаралды 765
Ransomware As Fast As Possible
5:10
Techquickie
Рет қаралды 452 М.
Azure AD Okta Differences
8:49
Finchloom
Рет қаралды 4,4 М.
MGM & Defcon Venue hack: BlackCat Ransomware
6:27
The PC Security Channel
Рет қаралды 25 М.
Cyber Asset Attack Surface Management: CAASM Explained
3:18
Technology Leadership
Рет қаралды 1,2 М.
How to Defend Against Pegasus Spyware Explained
7:45
Technology Leadership
Рет қаралды 5 М.