<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Okta Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Okta.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction</title><link>https://elastic.co/security-labs/agentic-soc-token-budget-architecture</link><guid isPermaLink="false">cst-3189</guid><description>Elastic InfoSec compares two architectural approaches for agentic security operations centers: a single agent with a library of skills versus a fleet of specialized agents orchestrated through deterministic workflows. Testing on 36,822 real production investigations shows the specialized agent approach costs $0.69 per alert triage versus $3.42 for the single-agent method, a 5.7x difference at scale. The choice between architectures depends on investigation patterns, team maturity, and whether analysts need flexible on-demand skill loading or deterministic methodologies.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI Is a Non-Human Identity Problem Wearing a Different Name Badge</title><link>https://reliaquest.com/blog/shadow-ai-non-human-identity-problem</link><guid isPermaLink="false">cst-3201</guid><description>Shadow AI integrated into engineering and data workflows presents a distinct security risk that differs from consumer chatbot usage. Tools connected to source code repositories, CI/CD pipelines, cloud environments, and production systems can operate through existing employee credentials without appearing as separate accounts in identity systems. Detection requires shifting focus from browser-based activity toward non-human identities and service accounts with privileged access.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Rockwell Automation FactoryTalk Services Platform</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-202-07</link><guid isPermaLink="false">cst-2938</guid><description>Rockwell Automation disclosed a critical vulnerability (CVE-2026-10714) in FactoryTalk Services Platform v6.60 that allows attackers to bypass JWT signature validation and forge authentication tokens. An authenticated low-privilege user could exploit this flaw to impersonate any authorized user, gaining unauthorized access to system configurations and permissions. Rockwell released patches, including a February 2026 roll-up and individual RAID 1158263, to remediate the issue.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>AI agents are still logging in as humans</title><link>https://helpnetsecurity.com/2026/07/21/report-enterprise-ai-identity-risk</link><guid isPermaLink="false">cst-2881</guid><description>Most large enterprises now operate multiple AI platforms simultaneously across departments, creating fragmented technology stacks with both sanctioned and personal accounts. Okta tracking data from over 20,000 organizations since June 2022 shows widespread use of mixed vendor environments where developers, marketers, and analysts rely on different AI tools. This proliferation of independent AI logins increases the complexity of identity and access management across organizations.</description><pubDate>Tue, 21 Jul 2026 04:30:16 GMT</pubDate></item><item><title>HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload</title><link>https://bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload</link><guid isPermaLink="false">cst-2776</guid><description>A vulnerability called HollowByte enables unauthenticated attackers to trigger denial-of-service conditions on OpenSSL servers using an 11-byte malicious payload. The flaw causes excessive memory consumption on affected servers, degrading availability without requiring authentication or complex exploitation techniques.</description><pubDate>Fri, 17 Jul 2026 17:56:21 GMT</pubDate></item><item><title>Entra passkey enrollment vishing targets Microsoft 365 users</title><link>https://bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users</link><guid isPermaLink="false">cst-2185</guid><description>A threat actor is targeting Microsoft 365 users with vishing (voice phishing) attacks that impersonate security personnel and request enrollment of a new Entra passkey. The campaign affects organizations across multiple sectors.</description><pubDate>Wed, 08 Jul 2026 16:47:25 GMT</pubDate></item><item><title>Welcome to BlackFile: Inside a Vishing Extortion Operation</title><link>https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation</link><guid isPermaLink="false">cst-312</guid><description>Google Threat Intelligence Group identified UNC6671, operating under the BlackFile brand, conducting a large-scale extortion campaign targeting organizations across North America, Australia, and the UK through voice phishing and single sign-on compromise. The group uses adversary-in-the-middle techniques to capture credentials and multi-factor authentication (MFA) codes in real-time, gaining access to cloud environments like Microsoft 365 and Okta to exfiltrate data for extortion. UNC6671 employs social engineering pretexts such as mandatory passkey migrations and MFA updates, along with lookalike credential harvesting domains, to deceive employees into providing access.</description><pubDate>Fri, 15 May 2026 14:00:00 GMT</pubDate></item><item><title>Your UEBA is lying to you: Why entity record quality decides everything</title><link>https://elastic.co/security-labs/ueba-entity-record-quality-analytics</link><guid isPermaLink="false">cst-625</guid><description>User and entity behavior analytics (UEBA) systems depend critically on the quality of entity records representing users, hosts, and services, yet most implementations get this foundation wrong from the start. The article examines two common failure modes: treating all instances of a username as a single entity (creating noise from shared accounts), and requiring identity provider integration only (leaving most environments invisible). A third approach using host-scoped identity with proper governance can balance meaningful signal detection against false positives.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security</title><link>https://elastic.co/security-labs/ai-esql-detection-rule-creation</link><guid isPermaLink="false">cst-626</guid><description>Elastic Security has added AI-powered detection rule creation that allows analysts to describe threats in plain English and automatically generates validated Elasticsearch Query Language (ES|QL) rules with MITRE ATT&amp;CK mappings and severity recommendations. The capability is built directly into the rule creation workflow, eliminating the need to learn query syntax or leave the platform. This addresses the growing gap between attack speed and detection engineering capacity by reducing the friction required to write and deploy new detection rules.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate></item><item><title>LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?</title><link>https://sentinelone.com/labs/labscon25-replay-are-your-chinese-cameras-spying-for-you-or-on-you</link><guid isPermaLink="false">cst-609</guid><description>Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.</description><pubDate>Wed, 22 Apr 2026 22:00:15 GMT</pubDate></item><item><title>ShinyHunters Fast-Tracks SaaS Access with Subdomain Impersonation</title><link>https://reliaquest.com/blog/threat-spotlight-shinyhunters-fast-tracks-saas-access-subdomain-impersonation</link><guid isPermaLink="false">cst-2202</guid><description>ShinyHunters is shifting from lookalike domain registration to subdomain impersonation tactics, hiding target organization branding in subdomains of generic SSO-themed domains to evade traditional domain monitoring. The group combines this with mobile-optimized phishing lures, outsourced spam and voice operations, and reused stolen CRM/ERP data to accelerate compromise of SaaS environments through session theft and help-desk MFA resets.</description><pubDate>Thu, 26 Feb 2026 18:00:00 GMT</pubDate></item><item><title>Protect your Okta identities with Wiz</title><link>https://wiz.io/blog/wiz-extends-support-to-okta</link><guid isPermaLink="false">cst-1539</guid><description>Wiz announced an extension of its security capabilities to include Okta identity management, offering visibility and risk assessment through its Security Graph platform. The integration provides real-time threat detection specifically for Okta environments.</description><pubDate>Wed, 23 Oct 2024 14:00:00 GMT</pubDate></item><item><title>Wiz expands board and executive team with top security leaders from DocuSign, Aon, Meta and Okta</title><link>https://wiz.io/blog/wiz-expands-board-and-executive-team-with-top-security-leaders</link><guid isPermaLink="false">cst-1790</guid><description>Wiz, a cloud security company, has added Emily Heath to its board of directors and expanded its executive team with experienced security leaders from major technology and professional services firms. The company is continuing to scale its leadership structure to support ongoing growth.</description><pubDate>Wed, 10 Aug 2022 13:12:01 GMT</pubDate></item></channel></rss>