Okta Red Team

HTTP/2 Crash: A Denial of Service (DoS) in HTTP/2 Flow Control

The Okta Red Team discovered a Denial of Service (DoS) vulnerability in HTTP/2 flow control.
Okta Red Team

OpenSSL HollowByte: A DoS Hiding in 11 Bytes

The Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL.
Okta and Tom Simpson and Jordan Ruocco and Julie Agnes Sparks and Greg Foss

Datadog and Okta Combine for New Customer Detections

Okta and Datadog have collaborated to enhance the Out-of-the-Box (OotB) detection capabilities of Datadog’s Cloud SIEM by including rules from the Okta Security Detection Catalog. These rules have been engineered to enable the identification of identity-related threats with minimal configuration.
Okta

Detecting OpenClaw at Sign-In

Okta Verify has a neat trick under the hood that can help you identify the use of personal AI assistants and other "not just yet" software.
Rob Gil and Naveed Mirza and Brandon Iske

Okta Hardening Guide Updated to Secure Non-Human Identities

Version 1.1 of the Okta Security Technical Implementation Guide (STIG) provides U.S. government agencies additional hardening recommendations related to network security and non-human identities.
Okta Customer Audit

Okta Pooled Security Audits: a One-Year Retrospective

Okta and its customers are benefitting from "pooled" security audits.
Brett Winterford

Account Recovery, without Password Resets

Temporary Access Codes provide an opportunity to constrain the ability of help desk staff to reset user passwords and MFA factors.
Okta

Okta’s Response to React2Shell

Read on for Okta’s response to React2Shell (CVE-2025-55182) and to learn more about actions required by developers.
Houssem Eddine Bordjiba

Uncloaking VoidProxy: a Novel and Evasive Phishing-as-a-Service Framework

Take a peek inside the latest AitM phishing kit.
Daniel López

Attackers Target Hotelier Accounts in Malvertising and Phishing Campaign

Russia-linked campaign targets hospitality and vacation rental providers.
Page 1 of 9