<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Okta and Microsoft incidents by LAPSUS$ in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50324#M503</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1086253963"&gt;@AndreaMoore&lt;/a&gt;Definitely a good one, however it also good to see Okta actually agree that they did the wrong thing, by keeping the situation quiet to the rest of the world for a prolonged period.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The made a "mistake"&amp;nbsp; &lt;A href="https://venturebeat.com/2022/03/25/okta-on-handling-of-lapsus-breach-we-made-a-mistake/" target="_blank"&gt;https://venturebeat.com/2022/03/25/okta-on-handling-of-lapsus-breach-we-made-a-mistake/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least they acted quickly to remedy the situation too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 20:30:32 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2022-03-30T20:30:32Z</dc:date>
    <item>
      <title>Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50259#M494</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you feel about the Okta and Microsoft incident outed by LAPSUS$?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/open-letter-okta-amit-yoran/?trackingId=p3x2Rvmp%2FPqiUhfPOyWBiA%3D%3D" target="_blank"&gt;https://www.linkedin.com/pulse/open-letter-okta-amit-yoran/?trackingId=p3x2Rvmp%2FPqiUhfPOyWBiA%3D%3D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.digitalshadows.com/blog-and-research/the-okta-breach-what-we-know-so-far/" target="_blank"&gt;https://www.digitalshadows.com/blog-and-research/the-okta-breach-what-we-know-so-far/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your organisation a victim?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you coping with the incident Response?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could Okta have done better?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:08:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50259#M494</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50265#M495</link>
      <description>&lt;P&gt;I like to the sentence "&lt;SPAN&gt;Trust is built on transparency and corporate responsibility, and demands both"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I&amp;nbsp;don't know, but very likely the CISO of Okta will have (is having) a&amp;nbsp;tough time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Honestly by not reporting and&amp;nbsp;disclosing is really bad and until&amp;nbsp;LAPSUS$ call upon, that is the worst&amp;nbsp;&lt;/SPAN&gt;nightmare. Being compromise is bad (for sure), but this even look worst.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 15:40:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50265#M495</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2022-03-24T15:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50276#M496</link>
      <description>&lt;P&gt;Great links, thanks for sharing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a note from the CSO of OKTA in which he lays out the timelines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/" target="_blank"&gt;https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder how long he will be in place?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 18:58:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50276#M496</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-03-25T18:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50306#M500</link>
      <description>&lt;P&gt;Seven teens arrested in relation to this attack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theverge.com/2022/3/24/22994563/lapsus-hacking-group-london-police-arrest-microsoft-nvidia" target="_blank"&gt;https://www.theverge.com/2022/3/24/22994563/lapsus-hacking-group-london-police-arrest-microsoft-nvidia&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 21:39:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50306#M500</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-03-28T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50312#M501</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;My favorite part of that article you shared is the quote from the father (last paragraph of the article).&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;"He’s never talked about any hacking, but he is very good on computers and spends a lot of time on the computer,” the father said, according to&amp;nbsp;&lt;I&gt;BBC News&lt;/I&gt;. “I always thought he was playing games. We’re going to try to stop him from going on computers.”&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:58:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50312#M501</guid>
      <dc:creator>AndreaMoore</dc:creator>
      <dc:date>2022-03-29T13:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50324#M503</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1086253963"&gt;@AndreaMoore&lt;/a&gt;Definitely a good one, however it also good to see Okta actually agree that they did the wrong thing, by keeping the situation quiet to the rest of the world for a prolonged period.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The made a "mistake"&amp;nbsp; &lt;A href="https://venturebeat.com/2022/03/25/okta-on-handling-of-lapsus-breach-we-made-a-mistake/" target="_blank"&gt;https://venturebeat.com/2022/03/25/okta-on-handling-of-lapsus-breach-we-made-a-mistake/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least they acted quickly to remedy the situation too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 20:30:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50324#M503</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-03-30T20:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50486#M521</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a deep and long analysis on the Okta incident, with many lessons to be learnt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But will it be learnt and how will others learn from this experience?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://siliconangle.com/2022/04/09/ripple-effects-okta-security-breach-worse-think/" target="_blank" rel="noopener"&gt;https://siliconangle.com/2022/04/09/ripple-effects-okta-security-breach-worse-think/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 20:23:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50486#M521</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-04-11T20:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Okta and Microsoft incidents by LAPSUS$</title>
      <link>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50501#M522</link>
      <description>&lt;P&gt;Good sharing and interesting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the CISO's comments are fair. The technical damage is minimal but it's the damage to the trust and reputation and this is a perfect PR disaster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust is built on Transparency, Accountability and Assurance.&lt;/P&gt;&lt;P&gt;What does Okta give customer?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 03:16:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Okta-and-Microsoft-incidents-by-LAPSUS/m-p/50501#M522</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2022-04-12T03:16:31Z</dc:date>
    </item>
  </channel>
</rss>

