Warning: Undefined array key "HTTP_ACCEPT_LANGUAGE" in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/load.php on line 2057

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rank-math domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/functions.php on line 6114
Okta revises LAPSUS$ impact upwards to potentially 2.5% of customers - Best Business Review Site 2024

Okta revises LAPSUS$ impact upwards to potentially 2.5% of customers

[ad_1]

okta.jpg

Okta has again updated its blog post related to the LAPSUS$ intrusion from January first revealed by the hacking gang on Tuesday.

“After a thorough analysis of these claims, we have concluded that a small percentage of customers — approximately 2.5% — have potentially been impacted and whose data may have been viewed or acted upon. We have identified those customers and are contacting them directly,” Okta CSO David Bradbury said.

“If you are an Okta customer and were impacted, we have already reached out directly by email.”

Earlier this month in its fourth-quarter results, the company said it had 15,000 customers, of which 2.5% is 375.

The company said it would be conducting a pair of technical webinars on the event on Wednesday.

See also: Okta: Lapsus$ attackers had access to support engineer’s laptop

For its part, LAPSUS$ said it gained access to a superuser portal that could reset the password and multifactor authentication of 95% of clients.

“For a company that supports zero-trust, support engineers seem to have excessive access to Slack? 8.6k channels?” the group said.

“The potential impact to Okta customers is NOT limited, I’m pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.”

The group called on Okta to hire a cybersecurity firm and to publish any report they complete. It also claimed Okta was storing AWS keys within Slack.

LAPSUS$ also added that many of its members were on holidays for the rest of the month.

“We might be quiet for some times,” the group said.

“Thanks for understand us — we will try to leak stuff ASAP.”

Meanwhile at Redmond: Microsoft confirms LAPSUS$ hit account with limited access after gang released alleged Bing and Cortana source

Speaking to ZDNet last week, Cisco advisory CISO Helen Patton said CISOs were separating themselves operationally from breach reporting requirements.

“So now we’ve got lawyers who are making a decision about whether something is material enough to require a report, which is not really the spirit of the regulation. But I’ve seen it in Australia, and I’m seeing it overseas as well,” she said.

“This is a coping mechanism because the reporting requirements are sort of vague.”

Patton said due to legal folk wanting to contain events as much as possible, they would start low and escalate the impact of events rather than starting high and walking back.

“That puts the rest of the rest of us at risk, actually,” the advosry CISO said.

“So the question is, what is the right level to go with? Do you oversell it or undersell it, in order to not only protect yourself, but protect the ecosystem that you’re working in?”

“We are rewarded by underselling … in a lot of ways reputationally, legally, but from a risk perspective, we might want to actually oversell it because that gets more people on alert faster and hopefully gives you a faster response.”

Patton said companies that issued multiple upwards revisions could appear as though they did not know what they were doing.

“It’s not until you’ve had a certain amount of time to explore the incident, respond to the incident, learn from the incident that you really have good quality information,” she said.

“But our regulators want us to tell them immediately when something looks funny. And there’s lots of things that look funny in our environments, because our environments they’re inherently odd.

“They’re going to get a lot of really bad signals early on, and we’re going to have to work out how do you talk about that publicly when the information is really asymmetrical in terms of what you know, and what’s actually happening. It’s a problem.”

Updated at 01:35pm AEDT, 23 March 2022: Added further information on LAPSUS$.

Related Coverage

[ad_2]

Source link

slot gacor slot gacor togel macau slot hoki bandar togel slot dana slot mahjong link slot link slot777 slot gampang maxwin slot hoki slot mahjong slot maxwin slot mpo slot777 slot toto slot toto situs toto toto slot situs toto situs toto situs toto situs toto slot88 toto slot slot gacor thailand slot bet receh situs toto situs toto slot toto slot situs toto situs toto situs toto situs togel macau toto slot slot demo slot pulsa slot pragmatic situs toto deposit dana 10k surga slot toto slot link situs toto situs toto slot situs toto situs toto slot777 slot gacor situs toto slot slot pulsa 10k toto togel situs toto slot situs toto slot gacor terpercaya slot dana slot gacor pay4d agen sbobet kedai168 kedai168 deposit pulsa situs toto slot pulsa situs toto slot pulsa situs toto situs toto situs toto slot dana toto slot situs toto slot pulsa toto slot situs toto slot pulsa situs toto situs toto situs toto toto slot toto slot slot toto akun pro maxwin situs toto slot gacor maxwin slot gacor maxwin situs toto slot slot depo 10k toto slot toto slot situs toto situs toto toto slot toto slot toto slot toto togel slot toto togel situs toto situs toto toto slot slot gacor slot gacor slot gacor situs toto situs toto cytotec toto slot situs toto situs toto toto slot situs toto situs toto slot gacor maxwin slot gacor maxwin link slot 10k slot gacor maxwin slot gacor slot pulsa situs slot 10k slot 10k toto slot toto slot situs toto situs toto situs toto bandar togel 4d toto slot