TL;DR
- Okta Breached via Stolen Access Tokens from Support Unit
- Brave Browser Secretly Installs VPN Without User Consent
- Over 40,000 Admin Portal Accounts Use 'admin' as a Password
- Critical SolarWinds Vulnerabilities Enable Unauthorized Network Takeover
- Curl Vulnerabilities: A Mixed Bag of Risks and Hype
Okta Breached via Stolen Access Tokens from Support Unit
- Credential Abuse and Data Exposure: Hackers exploited a stolen credential to access Okta's support case management system. They viewed HAR (HTTP Archive) files containing sensitive cookies and session tokens. These tokens could be used for impersonation attacks, posing a significant risk to Okta's client base.
- Third-Party Impact and Containment: Cloudflare detected unauthorized access to their Okta instance, originating from a compromised token at Okta. They used their Zero Trust Access Gateway and Data Loss Prevention tools to contain the incident swiftly, preventing any customer data breach.
- Lag in Okta's Incident Response: BeyondTrust detected an unauthorized attempt to create an admin account in their Okta environment on October 2, 2023. They alerted Okta, but the company took 16 days to fully contain the breach. This delay exposed a critical gap in Okta's incident response capabilities.
- Immediate Actions and Long-Term Recommendations: Okta revoked compromised session tokens and advised sanitizing credentials. However, Cloudflare and BeyondTrust recommend more robust measures, such as hardware-based MFA and immediate action on compromise reports. The incident calls for a re-evaluation of Okta's security protocols, including faster response times and mandatory hardware keys for all system accesses.
Brave Browser Secretly Installs VPN Without User Consent
- VPN Components in Windows Services: Brave's VPN service is automatically installed as part of the browser setup on Windows. Two services, labeled as "Brave VPN" and "Brave WireGuard," appear in the Windows Services Manager. These services remain dormant unless activated by a subscription.
- Admin Rights and Installation Behavior: The VPN services are installed with administrative rights, making them harder to remove. An update to Brave could potentially reinstate these services even if manually removed.
- VPN Service Architecture: The VPN service is not free and is part of Brave's Firewall + VPN package. Despite being dormant, the services are set to "manual" and "manual trigger start," meaning they can be activated if the user subscribes to Brave's VPN.
- Security Concerns: The auto-installation of VPN services could potentially be exploited as an attack vector. It also raises questions about software integrity and the ethical implications of installing services without explicit user consent