logo

Okta Warns Once Again of Credential-Stuffing Attacks

ID: 945d22fc-1564-59ff-8b80-f3cac26bb8cf

STIX ID: report--945d22fc-1564-59ff-8b80-f3cac26bb8cf

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-05-30

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Okta warned of credential-stuffing attacks observed beginning April 15 that targeted the cross-origin authentication (CORS) feature of its Customer Identity Cloud; customers should monitor SCOA/FCOA/pwd_leak events in tenant logs and apply mitigations such as restricting permitted origins, enabling breached-password detection, enforcing MFA or passwordless/passkey authentication, and disabling cross-origin endpoints if unused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.