TrustedSec Okta Breach Recommendations
ID: a691653b-7c89-531d-8c14-bf6da73b7857
STIX ID: report--a691653b-7c89-531d-8c14-bf6da73b7857
Feed Name: TrustedSec blog
TrustedSec issued an urgent incident-response advisory after LAPSUS$ claimed compromise of Okta; the advisory recommends exporting and analyzing Okta system logs and remote access authentication logs, checking for anomalous geographic or “impossible travel” logins, auditing registered MFA devices and hardware token changes, rotating Okta administrator passwords, disabling suspect support/debug access, and disabling/resetting compromised accounts and sessions while investigating for lateral movement or data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
