Market Cap: $2.1713T 0.84%
Volume(24h): $40.4173B 15.17%
  • Market Cap: $2.1713T 0.84%
  • Volume(24h): $40.4173B 15.17%
  • Fear & Greed Index:
  • Market Cap: $2.1713T 0.84%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

Okta, Zscaler, and the Drift Attacks: A Tale of Two Security Strategies

Oct 06, 2025 at 06:00 pm

Okta, Zscaler, and the Drift Attacks: A Tale of Two Security Strategies

The recent Salesloft Drift attacks sent ripples through the cybersecurity world, with Okta and Zscaler finding themselves in the crosshairs. While both companies faced the same threat, their experiences diverged dramatically, offering valuable lessons in cybersecurity strategy. In mid-August, a widespread data theft campaign occurred over a 10-day period.

The Divergent Paths of Okta and Zscaler

Okta's proactive security measures successfully thwarted the attack, preventing any lasting damage. Zscaler, however, wasn't as fortunate, experiencing unauthorized access to both customer and internal company data. This stark contrast underscores the critical role of a robust and layered security approach.

Understanding the Attack

The attack, attributed to the threat group UNC6395, exploited vulnerabilities in Salesloft's GitHub account and Drift's Amazon Web Services environment. This allowed the attackers to obtain OAuth tokens used by Drift customers, granting them access to sensitive data on integrated platforms.

Okta's Proactive Defense

Okta's success stemmed from its proactive monitoring and IP address restrictions for API calls. By identifying and blocking unauthorized access attempts from outside its configured IP range, Okta effectively neutralized the threat. David Bradbury, Okta's chief security officer, emphasized the importance of automating IP restriction implementation to make it more accessible for companies.

Zscaler's Experience and Lessons Learned

Despite having discontinued its use of Drift a month prior to the attack, Zscaler was still vulnerable due to an active OAuth token. The company faced the exposure of customer data, including names, email addresses, and product licensing information. Sam Curry, Zscaler's CISO, highlighted the critical need for limiting IP address ranges for API queries and rotating tokens more frequently.

The Mystery of Token Theft

The exact method used to steal the OAuth tokens remains unclear. While Salesloft's investigation is ongoing, both Okta and Zscaler emphasize the need for stronger token security measures. As Bradbury noted, the internet's reliance on easily reusable tokens presents a significant vulnerability.

Collective Defense and the Future of API Security

Both Bradbury and Curry stressed the importance of collective defense and vendor accountability. APIs are becoming a major attack vector, requiring enhanced monitoring and preventative controls. Bradbury advocated for Demonstrating Proof of Possession (DPoP) as a mechanism to restrict token use and prevent theft. Curry emphasized that “APIs are becoming a new highway of access that we need more control over, and we need better control of collectively.”

A Call to Action

This incident serves as a wake-up call for security leaders to prioritize security features in vendor selection and demand higher standards from their SaaS providers. By working together and sharing lessons learned, the cybersecurity community can raise the bar for security and create a more resilient ecosystem.

So, next time you're thinking about your company's security posture, remember the tale of Okta and Zscaler. It's a reminder that in the world of cybersecurity, a proactive approach and a strong defense are always in style, and maybe a little bit of luck. Stay safe out there, folks!

Original source:cyberscoop

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Aug 03, 2026