Hackers Stole Access Tokens from Okta’s Support Unit

Credit to Author: BrianKrebs| Date: Fri, 20 Oct 2023 18:39:23 +0000

Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support platform for at least two weeks before the company fully contained the intrusion.

Read more

Attacks on 5G Infrastructure From User Devices: ASN.1 Vulnerabilities in 5G Cores

Credit to Author: Salim S.I.| Date: Fri, 20 Oct 2023 00:00:00 +0000

In the second part of this series, we will examine how attackers can trigger vulnerabilities by sending control messages masquerading as user traffic to cross over from user plane to control plane.

Read more

Clever malvertising attack uses Punycode to look like KeePass’s official website

Categories: Threat Intelligence

Tags: malvertising

Tags: keepass

Tags: punycode

Tags: malware

Tags: ads

Tags: google

Threat actors are doubling down on brand impersonation by using lookalike domain names.

(Read more…)

The post Clever malvertising attack uses Punycode to look like KeePass’s official website appeared first on Malwarebytes Labs.

Read more

Cisco IOS XE vulnerability widely exploited in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: Cisco

Tags: IOS X

Tags: remote management

Tags: vulnerability

Tags: CVE-2023-20198

Tags: webUI

Tags: http server

Tags: http secure-server

Researchers have found that a recently disclosed vulnerability in Cisco IOS XE has already rendered thousands of compromised devices.

(Read more…)

The post Cisco IOS XE vulnerability widely exploited in the wild appeared first on Malwarebytes Labs.

Read more