• Okta confirms code breach, but says no customer data was harmed

    From TechnologyDaily@1337:1/100 to All on Thu Dec 22 10:45:04 2022
    Okta confirms code breach, but says no customer data was harmed

    Date:
    Thu, 22 Dec 2022 10:34:25 +0000

    Description:
    Okta says breach does not affect its customers and that its services remain fully operational.

    FULL STORY ======================================================================

    Authentication giant Okta has now confirmed recent reports of a data breach affecting its internal code .

    In a press release , the company repeated the points given in a confidential email shared with its security contacts - namely, that someone managed to
    gain access to the companys GitHub repository, a breach of which Okta was notified in early December this year.

    After investigating the matter, Okta concluded that someone copied the source code parked in the repository, and moved to secure its premises by placing temporary restrictions and suspending all GitHub integrations with
    third-party applications. Okta Workforce Identity Cloud affected

    Further investigation uncovered that Oktas customers were not affected by the incident, including HIPAA, FedRAMP, and DoD customers, therefore, are not required to do anything. Okta does not rely on the confidentiality of its source code for the security of its services, the announcement reads. The
    Okta service remains fully operational and secure.

    The breach pertains to Okta Workforce Identity Cloud (WIC) code repositories, the company confirmed, adding that it does not pertain to any Auth0 (Customer Identity Cloud) products.

    Law enforcement agencies have been notified, the announcement concludes. Read more

    Okta confirms hundreds of customers could be affected by data breach


    Everything we know about Lapsus$ and Okta so far


    Check out the best endpoint protection services around

    Commenting on the news, Raj Samani, SVP Chief Scientist at Rapid7, said a company's source code is quite valuable, and as such, important to cybercriminals.

    "From our own research, we know that intellectual property is a popular
    target for threat actors with 12% of data disclosuresbetween April 2020 and February 2022 containing it," Samani said. "Stolen source code can be used to find hidden security vulnerabilities and launch further attacks on a
    business; therefore, it is crucial that such sensitive information is protected.

    This is not Oktas first rodeo. In March, notorious extortion group Lapsus$ announced it had breached Oktas administrative consoles and stolen customer data.

    And in September, Auth0 (owned by Okta) reported a similar incident, when a third-party individual managed to steal old source code. The method was never established, so it isn't known if any malware was involved. These are the
    best firewalls around



    ======================================================================
    Link to news story: https://www.techradar.com/news/okta-confirms-code-breach-but-says-no-customer- data-was-harmed


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)