logo

Okta warns of credential stuffing attacks targeting its CORS feature

ID: b4d7cc9c-81b6-53e5-bf18-131bbfcb7019

STIX ID: report--b4d7cc9c-81b6-53e5-bf18-131bbfcb7019

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-05-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Okta warns that since April 15, 2024 threat actors have been conducting large-scale credential-stuffing attacks targeting the Customer Identity Cloud cross-origin authentication (CORS) feature; Okta notified affected customers and provided detections (watch for 'fcoa', 'scoa', and 'pwd_leak' events) and mitigations including immediate credential rotation, disabling unused cross-origin authentication, enforcing MFA or passwordless phishing-resistant auth, and enabling breached-password detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.