#okta — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #okta, aggregated by home.social.
-
ReliaQuest Exposes ShinyHunters' Social Engineering Tactics
ReliaQuest sets the record straight: claims of a ransomware attack or breach are completely false. The company recently thwarted a social engineering scheme by ShinyHunters, swiftly investigating and publicly rebutting the misinformation.
#Shinyhunters #SocialEngineering #Ransomware #EmergingThreats #Okta
-
ReliaQuest foi alvo de um ataque de engenharia social que permitiu a cibercriminosos obterem acesso temporário ao seu painel de controlo no Okta. O grupo de extorsão ShinyHunters divulgou capturas de ecrã do painel da empresa na dark web. 🚨
-
Okta's latest proposal uses identity-scoped MCP tool lists to filter unused schemas before prompt construction. In some testing scenarios, it slashed token overhead by over 90% https://www.artificialintelligence-news.com/news/okta-targets-ai-agent-token-costs-with-mcp-scoping/ #okta #agenticai #enterpriseai #mcp #ai #tech
-
This article by #Okta is so bad it's funny:
https://www.okta.com/identity-101/evil-twin-attack/Not only do they bend over backwards to cram as many "hackers" there as possible (hackers are what editors crave!), but it also seems like they are not aware of HTTPS, HSTS, and how browsers warn users when credentials are being requested via unencrypted connections.
> [attacker] can see all the login details and save them for later use.
Not they can't. Stop parroting stuff that has not been true for a decade.
-
I recently filed a support case with #Okta in which I made three suggestions to them for minor but noticeable improvements to their SSO browser extension.
In response, the support rep told me I should submit my suggestions to the "ideas" section in the Okta Help Center.
This is annoying and dumb.
#tech #software #programming #ProductManagement #SoftwareQuality #TechIsShitDispatch (1/3) -
#TechIsShitDispatch
Let's talk about the overflowing wheelbarrow of shit I recently encountered while reinstalling a whole bunch of apps onto my #Android phone after deleting them for privacy reasons before going through customs. Buckle up, it's a wild ride.
#Signal #K9Mail #Slack #2FAS #Okta #Vivaldi #Microsoft #Wise #YubiKey #Synology #Jetpack #Automattic #Wordpress #LinkedIn
1/24 -
I would like to thank Mythos for my having to perform multi-factor gymnastics every day for every work mobile app:
* Please re-authenticate
* User ID
* BeyondIdentity Challenge (which never works)
* Open BI QR Code
* Screen Shot QR Code
* Open in Work Side Photos app
* Google Lens to read the QR code and turn into a URL
* Open the URL
* Approve BI
* Challenged with my phone's 8 digit PIN
* Challenged by Okta
* Accept the Okta Notification
* What was I just trying to do? -
🗽 I’ve just returned from a vacation in New York.
🤖 And I brought back something unexpected: not souvenirs, but a very concrete reflection on where we really are with AI.
🌃 In Times Square, next to Coca-Cola and Samsung, there was an ad for an AI platform.
In cafés, from Starbucks to Gregorys, anyone with an open laptop — students, developers, journalists — was interacting with Claude, Copilot or ChatGPT.
Not as a novelty. As normality.In the US, AI has already crossed the cultural point of no return.
📊 The data confirms it: 41% of American workers use GenAI for professional purposes, compared to ~20% of European companies. And the gap is even wider between large enterprises (55%) and SMEs (17%).
In my new article, I talk about:
🏙️ What I saw in Times Square and Manhattan cafés
📈 The real data behind the US vs Europe gap
⚠️ Shadow AI: why uncontrolled growth is the most underestimated risk
🔐 How governance and identity management are becoming the key to adopting AI sustainably🔗 Read the blog post here: https://iam.fabiograsso.net/blog/okta-ai-newyork/?utm_source=infosec.exchange&utm_medium=social&utm_campaign=2026q2_masto_push&utm_content=p16_okta_ai_newyork
Are you already governing AI agents in your organization? Or are you still in the “let’s try and see what happens” phase? Where do you see the biggest AI governance gap in your organization today?
-
SCIM (System for Cross-domain Identity Management: RFCs 7643 & 7644) is the standard way for an identity provider like #Okta or Azure AD to push users and groups into your application: who joined, who got deactivated, who got added to which group.
-
#UNC6783 extortionist hackers impersonate support staff, using fake Okta login pages and social engineering to access corporate systems and steal sensitive data, #Google warns.
Read: https://hackread.com/unc6783-hackers-fake-okta-pages-corporate-breach/
-
@[email protected]
On the plus side, step #1 of setting up things like an #AWS/#Azure/#GCP account — especially production ones — is to disable the ability to create IAM users (forcing the use of IAM-roles that are 2FA authenticated via a service like #Okta) …and the role-based authentication-tokens are typically TTLed to a couple hours.
Still, a "good" (suspicious-quotes) agent-setup would be pretty trivial to configure to snarf credentials from the relevant token-services. That triviality likely applies more broadly. -
Part of my #Monday work ritual is giving the ol' work laptop a refresh, which means shutting it down completely and powering it back on. But then it runs like slow ass, so I have to give it a reboot and then it's fine. Then once I log in with #Okta 853 times to get #Zscaler authenticated I'm off and running!
Gotta love #SSO.
-
ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs
#ShinyHunters #Okta
https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/ -
Okta, for an authentication system, has so many rough edges and bad user experiences.
In the portal, and click the Sign Out button? Yeah, doesn't do anything.
Already logged in, but touching something that requires 2FA? Tell the user that, and give them options on what 2FA to trigger.
My org doesn't allow Windows Hello, so if I login with that, having Okta Verify pop up, with a big "Windows Hello confirmation <disabled>" doesn't help me, I can't use that to 2FA.
-
Passwordless is finally happening, and users barely notice https://www.helpnetsecurity.com/2025/12/16/okta-mfa-security-shift-report/ #identitymanagement #authentication #cybersecurity #passwordless #report #News #Okta #MFA
-
👨💻🔐 Oh look, another enthralling tale of #AI slop from the tech wizards at #Okta, where #OAuth #vulnerabilities are as common as JavaScript frameworks. Apparently, injecting parameters into their #nextjs0auth project was so simple, even a chatbot could have written the patch. 🚀✨
https://joshua.hu/ai-slop-okta-nextjs-0auth-security-vulnerability #TechNews #HackerNews #ngated -
OktaでSalesforceをSAML連携させてシングルサインオン(SSO)してみた #okta
https://dev.classmethod.jp/articles/okta-salesforce-saml-sso-okta-kdpn/ -
Understanding Okta: A Complete Guide to Modern Identity and Access Management
https://www.xtivia.com/blog/understanding-okta-complete-guide-to-modern-identity-and-access-management/
#okta -
Interesting 🤔 Security leaders at #Okta and #Zscaler share lessons from Salesloft Drift attacks
https://cyberscoop.com/okta-zscaler-security-leaders-salesloft-drift-attacks/ #Infosec
-
North Korea’s IT workers are targeting firms beyond tech, crypto, and the U.S. https://www.helpnetsecurity.com/2025/10/01/north-korea-it-workers-worldwide/ #softwaredevelopment #financialindustry #insiderthreat #remoteworking #government #healthcare #NorthKorea #Don'tmiss #Australia #Singapore #Hotstuff #Germany #Canada #Europe #India #Japan #News #Okta #tips #USA #AI #UK
-
New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts https://hackread.com/voidproxy-phishing-service-bypasses-mfa-microsoft-google/ #Cybersecurity #PhishingScam #CyberAttack #Microsoft #VoidProxy #Security #Phishing #security #Google #PhaaS #AitM #Okta #MFA
-
Purple Teaming Okta Detection Virtual Workshop happening this Wednesday!
Join other security engineers and SOC analysts for practical Okta detection engineering on September 3rd.
You'll get live demonstrations of Okta log ingestion, hands-on experience building custom detection rules for identity threats, and the chance to test your detections with adversary emulation tools in individual lab environments.
Stop relying on rigid vendor solutions and start building detection capabilities tailored to your environment.