WebFi 4 Okta customers hit by campaign that gave attackers super admin control

WebFi 4 Okta customers hit by campaign that gave attackers super admin control

WEBFITECH  | MAGAZINE | NEWS | CRYPTO & MARKET | LATINO |⛅WEATHER | 🟢LIVE |

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors


WEBFI Hosting Service for lifetime - Onetime Donation - LifeTime Hosting Service for a lifetime - Onetime Donation - Lifetime License Are you the owner of your domain? With your Donation to WEBFI.NET, you get a space on our servers under the WordPress format, with unlimited disk space, unlimited bandwidth, premium access to premium themes galleries and Premium WordPress Plugins, and unlimited HTTPS WildCard protocol. Immediate activation 24 hours after your donation is confirmed. Lifetime license - One-Time Donation. Donations are processed by PayPal and PayPal Guest so you don't need a PayPal account, you can safely use debit, credit, or gift cards. The concept is simple and runs in as little as 24 hours *ONETIME Donation *WordPress-PRO Platform. *Unlimited Disk Space*Unlimited Bandwidth *SSL Wildcard Certificate *99.5% UPTIME *WordPress Premium PRO All Access Platform, Themes, and Plugins *24Hrs activation time from any phone or computer via www.1877.link or @ctmmagazine DM 0r in our customer service board WEBFI is aimed at anyone who seeks to be informed and entertained or wants to publish their opinions and news in real time. This is an Open and Public website, your opinions and post can be seen at the front on the home page and directories. webfinet website ownership license for lifetime With your Donation to WEBFI.NET, you get a space on our servers under the WordPress format, with unlimited disk space, unlimited bandwidth, premium access to premium themes galleries and Premium WordPress Plugins, and unlimited HTTPS WildCard protocol. Immediate activation 24 hours after your donation is confirmed. Lifetime license - One-Time Donation. Donations are processed by PayPal and PayPal Guest so you don't need a PayPal account, you can safely use debit, credit, or gift cards. The concept is simple and runs in as little as 24 hours *ONETIME Donation *WordPress-PRO Platform. *Unlimited Disk Space*Unlimited Bandwidth *SSL Wildcard Certificate *99.5% UPTIME *WordPress Premium PRO All Access Platform, Themes, and Plugins *24Hrs activation time from any phone or computer via www.1877.link  or @ctmmagazine DM 0r in our customer service board Get your own space to host your website for a single donation that allows you to host your project for life without the need for recurring payments, you only pay for your domain annuities to your domain provider and that's it!
LIVE

Getty Images

Authentication service Okta said four of its customers have been hit in a recent social-engineering campaign that allowed hackers to gain control of super administrator accounts and from there weaken or entirely remove two-factor authentication protecting accounts from unauthorized access.

The Okta super administrator accounts are assigned to users with the highest permissions inside an organization using Okta’s service. In recent weeks, Okta customers’ IT desk personnel have received calls that follow a consistent pattern of social engineering, in which attackers pose as a company insider in an attempt to trick workers into divulging passwords or doing other dangerous things. The attackers in this case call service desk personnel and attempt to convince them to reset all multi-factor authentication factors assigned to super administrators or other highly privileged users, Okta said recently.

Two-factor authentication and multi-factor authentication, usually abbreviated as 2FA and MFA, require a biometric, possession of a physical security key, or knowledge of a one-time password in addition to a normally used password to access an account.

Targeting users with the highest of permissions

When successful, the attackers used the compromised super administrator accounts to assign higher privileges to other accounts and/or reset enrolled authenticators in existing administrator accounts. In some cases, the threat actor also removed second-factor requirements from authentication policies. The threat actor also assigned a new app to access resources within the compromised organization. These “impersonation apps” were created after enrolling a new identity provider, which customers integrate into their Okta account.

“Given how powerful this is, access to create or modify an Identity Provider is limited to users with the highest permissions in an Okta organization—Super Administrator or Org Administrator,” Okta officials wrote. “It can also be delegated to a Custom Admin Role to reduce the number of Super Administrators required in large, complex environments. These recent attacks highlight why protecting access to highly privileged accounts is so essential.”

An Okta representative, citing company Chief Security Officer David Bradbury, said in an email that four customers were affected within the three-week period from July 29, when the company began tracking the campaign, through August 19. Bradbury didn’t elaborate.

Attacks such as the ones here are serious because authentication companies often hold or safeguard multiple high-privileged credentials inside sensitive organizations. Last year’s breach of 2FA provider Twilio, for instance, allowed the attackers to hack at least 136 of the company’s customers.

As was the case in that campaign, the attackers targeting Okta customers are well-resourced. In some cases, they already possessed passwords to the high-access accounts. In others, they were able to change the authentication flow for customers’ Active Directory, which is federated through Okta. To complete the compromise, the attackers first needed to trick customers into lowering the MFA protections standing in their way.

The Okta post summarized the attacker techniques, tactics, and procedures this way:

  • The threat actor would access the compromised account using anonymizing proxy services and an IP and device not previously associated with the user account.
  • Compromised Super Administrator accounts were used to assign higher privileges to other accounts, and/or reset enrolled authenticators in existing administrator accounts. In some cases, the threat actor removed second factor requirements from authentication policies.
  • The threat actor was observed configuring a second Identity Provider to act as an “impersonation app” to access applications within the compromised Org on behalf of other users. This second Identity Provider, also controlled by the attacker, would act as a “source” IdP in an inbound federation relationship (sometimes called “Org2Org”) with the target.
  • From this “source” IdP, the threat actor manipulated the username parameter for targeted users in the second “source” Identity Provider to match a real user in the compromised “target” Identity Provider. This provided the ability to Single sign-on (SSO) into applications in the target IdP as the targeted user.

The post provided a list of IP addresses and other traces left behind by the attackers. Okta customers can use the indicators of compromise to detect if they have been targeted in the same campaign. Okta didn’t identify the four affected customers or say what attackers could do once they had access to the customer resources. Based on the hack of Twilio and the resources of the attackers, it wouldn’t be surprising if the number of affected customers rises in the coming days.



Source link

WEBFI – WEBFI Unstoppable Private Websites – Ownership for lifetime. Live News Magazine Own a private website for life with WEBFI NET. Our private servers offer the best in security and performance, and our lifetime license means you'll never have to worry about renewing your hosting again. Plus, get unlimited access to our Live News Online Magazine, which features a brief look at national & global news from all points of view, plus entertainment, live weather radar, and streaming. No registration or download is required. Available in English and Spanish. WEBFINET Private Servers since 2018 Web Hosting lifetime license info via TEXT-WhatsApp. Former Ctm Magazine 2009 X-@ctmmagazine

🏠 | Tech | Live🟢 | Magazine | News | Crypto | Weather | 🇪🇸 | 🍿 | TermsPrivacy |

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Unstoppable Private Websites – Ownership for lifetime. Live News Magazine. Own a private website for life with WebFi. Our private servers offer the best in security and performance,and our lifetime license means you'll never have to worry about renewing your hosting again.

Get your own Webfi space to host your website for a single donation that allows you to host your project for life without the need for recurring payments, You only pay for your domain annuities to your domain provider and that's it! LEARN MORE

⚖News Balance🇺🇲

The WEBFI algorithm collects the active news on the Internet and temporarily exposes it on this platform, both in written and video format. WEBFI Network - News Balance Security, does not show advertising in its contents, does not redirect to other sites, and filters any graphic content evaluated as insecure, sensitive, or private. In this way, we ensure that all visitors are informed without distraction and safely. The opinions and content issued on this platform do not necessarily reflect the opinion, philosophy, or vision of WEBFINET. We strongly believe in freedom of speech.


WEBFI – WEBFI Unstoppable Private Websites – Ownership for lifetime. Live News Magazine Own a private website for life with WEBFI NET. Our private servers offer the best in security and performance, and our lifetime license means you'll never have to worry about renewing your hosting again. Plus, get unlimited access to our Live News Online Magazine, which features a brief look at national & global news from all points of view, plus entertainment, live weather radar, and streaming. No registration or download is required. Available in English and Spanish. WEBFINET Private Servers since 2018 Web Hosting lifetime license info via TEXT-WhatsApp. Former Ctm Magazine 2009 X-@ctmmagazine
Contact us
  • WEBFI
  • LIVE WORLD & USA
  • TODAY
  • LIVE NEWS-STORIES
  • TECHNOLOGY UPDATE
  • CRYPTO NEWS
  • LATINO ONLINE
  • ENTERTAINMENT
  • MOVIES
  • Language Learning Center
  • LATINO
  • CRYPTO & MARKET
  • TECH
  • NEWS
  • MAGAZINE
  • WEATHER
  • LIVE
  • WEBFI-HOME
error: WEBFI NETWORK website Protection and Privacy for Publishers. This content may not be copied.