HomeSecurityOkta warns of credential stuffing attacks in CORS

Okta warns of credential stuffing attacks in CORS

Okta is warning that a Customer Identity Cloud (CIC) is being targeted by credential stuffing attacks, stating that multiple customers have been targeted since April.

See also: Okta: Significant increase in credential stuffing attacks on customers

Okta credential stuffing attacks

Okta is a leading identity and access management company that provides cloud-based solutions for secure access to applications, websites, and devices. It offers single sign-on (SSO), multi-factor authentication (MFA), a global catalog, API access management, and lifecycle management.

A credential stuffing attack occurs when malicious actors create large lists of usernames and passwords stolen in data breaches or by credential- stealing malware and then use them to try to compromise online accounts.

Okta says it detected credential stuffing attacks starting on April 15, 2024 , which targeted endpoints using Customer Identity Cloud 's multi-origin authentication feature .

" Okta has determined that the Customer Identity Cloud (CIC) capability is a vulnerable target for threats orchestrating credential stuffing attacks ," Okta said in a statement

See also: Roku: 576,000 accounts compromised through credential stuffing

“As part of our commitment to Okta's secure identity and our commitment to customer security , we regularly monitor and review potentially suspicious activity and proactively send alerts to customers“

FBI: Home proxies exploited in credential stuffing attacks

Okta's Cross-Origin Resource Sharing (CORS) feature allows customers to add JavaScript to their websites and applications to send authentication calls to Okta's API. For this feature to work, customers must grant access to the URLs from which cross-origin requests can originate.

Okta states that these URLs are targeted by credential stuffing attacks and should be disabled if not in use.

The company has notified customers targeted in these attacks with remediation guidance for securing their accounts.

It's worth noting that Okta warned its customer base about "unprecedented" credential stuffing attacks late last month, coming from the same threat actors that have been targeting Cisco Talos since March 2024.

See also: PetSmart: Warns customers about credential stuffing attack

How can users protect their accounts from credential stuffing attacks?

Users can protect their accounts from credential stuffing attacks, such as the one on Okta, by using strong and unique passwords for each account. A strong password should include a mix of uppercase and lowercase letters, numbers, and special characters. Using a password manager can help users create and store unique and strong passwords for each account, without having to remember them all. Enabling multi-factor authentication (MFA) adds an extra layer of security to accounts. Users should be careful with the emails and websites they visit, avoiding entering their credentials into suspicious or untrusted sources. Regularly updating the software and applications that users use can help protect against vulnerabilities that attackers could exploit.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS