Top 7 recs for responding to the Lapsus$ breach claims
ID: 0a67f6ce-8a0e-5ed3-bd45-719eca2ad6c1
STIX ID: report--0a67f6ce-8a0e-5ed3-bd45-719eca2ad6c1
Feed Name: Expel Blog
Threat Score
This advisory discusses the Okta/Lapsus$ compromise claims and Okta’s ongoing investigation (as of March 23, 2022), and provides seven prioritized recommendations—rotate privileged credentials and API tokens, restrict Okta support access, review admin/authentication logs for specific event types, enforce and expand MFA (prefer FIDO), configure network zones, establish/test incident response retainers and plans, and communicate transparently with stakeholders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
