4 ms·
Your entire service is based on the security of your product. You owe everyone more of an explanation. The Lapsus telegram clearly shows they are using an inter
by k4ch0w 5y ago
Your entire service is based on the security of your product. You owe everyone more of an explanation. The Lapsus telegram clearly shows they are using an internal Okta Admin tool to reset/disable passwords and 2FA. I'm more inclined to believe the evidence in front of my eyes than your statement.
It's clear some service team at Microsoft used Okta to SSO, or a contractor that did that's why they only got 37GB of code and Bing/Cortona not Windows OS or internal tools.
The group probably enumerated as much access from Okta as possible and when they had every juicy target decided to release it all for the lols. They probably have more in the works too.
I'd suggest everyone today revoke any Okta SSO sessions for your apps and force a new session as a precautionary measure.
- tuwtuwtuwtuw 5y ago> It's clear some service team at Microsoft used Okta to SSO, or a contractor that did that's why they only got 37GB of code and Bing/Cortona not Windows OS or internal tools. Did i miss some news or? I know Okta and Microsoft was compromised, but is there anything which shows it was related except for the hacker group and timing?
- k4ch0w 5y agoNo, just the timing and group. Pure speculation