Okta disclosed a security flaw that allowed unauthorized access to accounts with 52+ character usernames by bypassing password authentication if a stored cache key was detected, affecting users who logged in using the same browser. The vulnerability, introduced in a July 23 update, was only discovered and fixed on October 30, prompting Okta to advise affected customers to review their access logs. Although the issue didn’t impact organizations with multi-factor authentication, the company is urging users to monitor their accounts for any suspicious activity.
Full Article
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Security researcher Eaton Zveare informed TechCrunch about vulnerabilities in a carmaker's centralized dealer portal that allowed extensive access to customer and vehicle data. He demonstrated that these flaws enabled him to remotely seize control of a customer's account, including the ability to unlock their car. Want More Context? 🔎
Read more