Vulnerability Disclosure at Okta: Everything You Need to Know

Protecting our customers, partners, and other stakeholders has always been the Okta Security Team’s top priority. We have invested heavily in our security infrastructure in support of this mission, building a top-of-class internal application, and instituting both offensive and defensive security teams. But with every endeavor, it’s best to draw…

Investigating Modlishka Credential Attacks: Old Dog, New Tricks

You may have heard about a new phishing tool called Modlishka, and have questions about its potential impact on multi-factor authentication or single sign-on. To be clear, Modlishka is not a vulnerability in MFA or SSO. Rather, it is an automation tool designed to make it easier for attackers to phish your employees. In this post, I will outline…