
By Cade Metz
The San Francisco start-up’s valuation could triple in less than six months.
Published: October 19, 2023 at 06:00PM
from NYT Technology https://ift.tt/lcNQ3Js
via IFTTT

By Cade Metz
The San Francisco start-up’s valuation could triple in less than six months.
Published: October 19, 2023 at 06:00PM
from NYT Technology https://ift.tt/lcNQ3Js
via IFTTT
[New Episodes] Teenage friends find their lives upended by the wonders and horrors of puberty in this edgy comedy from real-life pals Nick Kroll and Andrew Goldberg.
from New On Netflix USA https://ift.tt/sZ9HA2L
via IFTTT
Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support platform for at least two weeks before the company fully contained the intrusion.

In an advisory sent to an undisclosed number of customers on Oct. 19, Okta said it “has identified adversarial activity that leveraged access to a stolen credential to access Okta’s support case management system. The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases.”
Okta explained that when it is troubleshooting issues with customers it will often ask for a recording of a Web browser session (a.k.a. an HTTP Archive or HAR file). These are sensitive files because in this case they include the customer’s cookies and session tokens, which intruders can then use to impersonate valid users.
“Okta has worked with impacted customers to investigate, and has taken measures to protect our customers, including the revocation of embedded session tokens,” their notice continued. “In general, Okta recommends sanitizing all credentials and cookies/session tokens within a HAR file before sharing it.”
The security firm BeyondTrust is among the Okta customers who received Thursday’s alert from Okta. BeyondTrust CEO Marc Maiffret said that alert came more than two weeks after his company alerted Okta to a potential problem.
Maiffret emphasized that BeyondTrust caught the attack earlier this month as it was happening, and that none of its own customers were affected. He said that on Oct 2., BeyondTrust’s security team detected that someone was trying to use an Okta account assigned to one of their engineers to create an all-powerful administrator account within their Okta environment.
When BeyondTrust reviewed the activity of the employee account that tried to create the new administrative profile, they found that — just 30 minutes prior to the unauthorized activity — one of their support engineers shared with Okta one of these HAR files that apparently contained a valid Okta session token, Maiffret said.
“Our admin sent that [HAR file] over at Okta’s request, and 30 minutes after that the attacker started doing session hijacking, tried to replay the browser session and leverage the cookie in that browser recording to act on behalf of that user,” he said.
Maiffret said BeyondTrust followed up with Okta on Oct. 3 and said they were fairly confident Okta had suffered an intrusion, and that he reiterated that conclusion in a phone call with Okta on October 11 and again on Oct. 13.
In an interview with KrebsOnSecurity, Okta’s Deputy Chief Information Security Officer Charlotte Wylie said Okta initially believed that BeyondTrust’s alert on Oct. 2 was not a result of a breach in its systems. But she said that by Oct. 17, the company had identified and contained the incident — disabling the compromised customer case management account, and invalidating Okta access tokens associated with that account.
Wylie declined to say exactly how many customers received alerts of a potential security issue, but characterized it as a “very, very small subset” of its more than 18,000 customers.
The disclosure from Okta comes just weeks after casino giants Caesar’s Entertainment and MGM Resorts were hacked. In both cases, the attackers managed to social engineer employees resetting the multi-factor login requirements for Okta administrator accounts.
In March 2022, Okta disclosed a breach from the hacking group LAPSUS$, a criminal hacking group that specialized in social-engineering employees at targeted companies. An after-action report from Okta on that incident found that LAPSUS$ had social engineered its way onto the workstation of a support engineer at Sitel, a third-party outsourcing company that had access to Okta resources.
Okta’s Wylie declined to answer questions about how long the intruder may have had access to the company’s case management account, or who might have been responsible for the attack. However, she did say the company believes this is adversary they have seen before.
“This is a known threat actor that we believe has targeted us and Okta-specific customers,” Wylie said.
This is a fast-moving story. Updates will be noted and timestamped here.
from Krebs on Security https://ift.tt/3jlUp8R
via IFTTT

By David Yaffe-Bellany
Prosecutors in the criminal fraud case have built the most intricate account to date of the cryptocurrency exchange’s frantic final days.
Published: October 19, 2023 at 06:00PM
from NYT Technology https://ift.tt/IisMj5w
via IFTTT

By Cade Metz
The San Francisco start-up’s valuation could triple in less than six months.
Published: October 20, 2023 at 10:01AM
from NYT Technology https://ift.tt/lcNQ3Js
via IFTTT

By Erin Griffith and Sapna Maheshwari
A start-up that offers fans a way to buy personalized videos from celebrities was supercharged by pandemic boredom and venture capital. All it had to do was grow forever.
Published: October 20, 2023 at 09:30AM
from NYT Technology https://ift.tt/9OFDaYT
via IFTTT
Add some color to your life, find accent lighting to match your mood, and transform the feel of your home with these decorative devices.
from Gear Latest https://ift.tt/Y2ZAcom
via IFTTT
The wedding of her niece prompts octogenarian Emilia to round up her extended family for a cross-country road trip in a run-down motor home.
from New On Netflix USA https://ift.tt/DT1kXHL
via IFTTT
[New Episodes] When three working-class teens enroll in an exclusive private school in Spain, the clash between them and the wealthy students leads to murder.
from New On Netflix USA https://ift.tt/O9rkjfB
via IFTTT
[Episodes Removed] A 14-year-old takes ownership of a toy company and hires a group of his friends to help him create amazing new toys.
from New On Netflix USA https://ift.tt/7PjiwGf
via IFTTT