時価総額: $2.5216T 6.50%
ボリューム(24時間): $137.3064B 8.71%
  • 時価総額: $2.5216T 6.50%
  • ボリューム(24時間): $137.3064B 8.71%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.5216T 6.50%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$75268.858698 USD

8.53%

ethereum
ethereum

$2363.950936 USD

5.45%

tether
tether

$0.999566 USD

0.03%

bnb
bnb

$664.951035 USD

6.43%

xrp
xrp

$1.312939 USD

19.10%

usd-coin
usd-coin

$0.999944 USD

0.01%

solana
solana

$90.762330 USD

7.09%

tron
tron

$0.338064 USD

1.46%

hyperliquid
hyperliquid

$73.234749 USD

2.61%

dogecoin
dogecoin

$0.083019 USD

11.21%

zcash
zcash

$600.124195 USD

8.72%

unus-sed-leo
unus-sed-leo

$9.273276 USD

-0.80%

chainlink
chainlink

$10.973069 USD

4.91%

monero
monero

$415.751478 USD

0.89%

cardano
cardano

$0.209467 USD

14.41%

暗号通貨のニュース記事

Okta、Zscaler、およびドリフト攻撃:2つのセキュリティ戦略の物語

2025/10/06 18:00

ドリフトの顧客をターゲットにした最近のサプライチェーン攻撃は、堅牢なセキュリティ対策の重要性を強調しています。 OktaとZscalerが同じ脅威を大きく異なる結果でナビゲートした方法を学びます。

Okta、Zscaler、およびドリフト攻撃:2つのセキュリティ戦略の物語

The recent Salesloft Drift attacks sent ripples through the cybersecurity world, with Okta and Zscaler finding themselves in the crosshairs. While both companies faced the same threat, their experiences diverged dramatically, offering valuable lessons in cybersecurity strategy. In mid-August, a widespread data theft campaign occurred over a 10-day period.

最近のSalesLoftドリフト攻撃は、サイバーセキュリティの世界に波紋を送り、OktaとZscalerは十字線で自分自身を見つけました。両社は同じ脅威に直面していましたが、彼らの経験は劇的に分岐し、サイバーセキュリティ戦略の貴重な教訓を提供しました。 8月中旬には、10日間にわたって広範囲にわたるデータ盗難キャンペーンが行われました。

The Divergent Paths of Okta and Zscaler

オクタとZscalerの分岐パス

Okta's proactive security measures successfully thwarted the attack, preventing any lasting damage. Zscaler, however, wasn't as fortunate, experiencing unauthorized access to both customer and internal company data. This stark contrast underscores the critical role of a robust and layered security approach.

OKTAの積極的なセキュリティ対策は、攻撃をうまく阻止し、永続的な損害を防ぎました。ただし、Zscalerはそれほど幸運ではなく、顧客データと内部企業データの両方に不正アクセスを経験しています。この厳しいコントラストは、堅牢で階層化されたセキュリティアプローチの重要な役割を強調しています。

Understanding the Attack

攻撃を理解する

The attack, attributed to the threat group UNC6395, exploited vulnerabilities in Salesloft's GitHub account and Drift's Amazon Web Services environment. This allowed the attackers to obtain OAuth tokens used by Drift customers, granting them access to sensitive data on integrated platforms.

脅威グループUNC6395に起因する攻撃は、SalesLoftのGitHubアカウントとDriftのAmazon Webサービス環境の脆弱性を活用しました。これにより、攻撃者はドリフト顧客が使用するOAUTHトークンを取得し、統合されたプラットフォーム上の機密データへのアクセスを許可することができました。

Okta's Proactive Defense

Oktaの積極的な防御

Okta's success stemmed from its proactive monitoring and IP address restrictions for API calls. By identifying and blocking unauthorized access attempts from outside its configured IP range, Okta effectively neutralized the threat. David Bradbury, Okta's chief security officer, emphasized the importance of automating IP restriction implementation to make it more accessible for companies.

OKTAの成功は、API呼び出しの積極的な監視とIPアドレスの制限に起因しています。構成されたIP範囲外から不正なアクセスの試みを特定してブロックすることにより、OKTAは脅威を効果的に中和しました。 OKTAの最高保障責任者であるDavid Bradburyは、企業にとってよりアクセスしやすくするためにIP制限の実装を自動化することの重要性を強調しました。

Zscaler's Experience and Lessons Learned

Zscalerの経験と学んだ教訓

Despite having discontinued its use of Drift a month prior to the attack, Zscaler was still vulnerable due to an active OAuth token. The company faced the exposure of customer data, including names, email addresses, and product licensing information. Sam Curry, Zscaler's CISO, highlighted the critical need for limiting IP address ranges for API queries and rotating tokens more frequently.

攻撃の1か月前にドリフトの使用を中止したにもかかわらず、ZscalerはアクティブなOAuthトークンのために依然として脆弱でした。同社は、名前、電子メールアドレス、製品ライセンス情報など、顧客データの露出に直面しました。 ZscalerのCISOであるSam Curryは、APIクエリと回転トークンのIPアドレス範囲をより頻繁に制限する重要な必要性を強調しました。

The Mystery of Token Theft

トークン盗難の謎

The exact method used to steal the OAuth tokens remains unclear. While Salesloft's investigation is ongoing, both Okta and Zscaler emphasize the need for stronger token security measures. As Bradbury noted, the internet's reliance on easily reusable tokens presents a significant vulnerability.

OAuthトークンを盗むために使用される正確な方法は不明のままです。 SalesLoftの調査は進行中ですが、OktaとZscalerの両方が、より強力なトークンセキュリティ対策の必要性を強調しています。 Bradburyが指摘したように、インターネットが簡単に再利用可能なトークンに依存していることは、大きな脆弱性を示しています。

Collective Defense and the Future of API Security

集合防衛とAPIセキュリティの未来

Both Bradbury and Curry stressed the importance of collective defense and vendor accountability. APIs are becoming a major attack vector, requiring enhanced monitoring and preventative controls. Bradbury advocated for Demonstrating Proof of Possession (DPoP) as a mechanism to restrict token use and prevent theft. Curry emphasized that “APIs are becoming a new highway of access that we need more control over, and we need better control of collectively.”

ブラッドベリーとカリーの両方は、集団防衛とベンダーの説明責任の重要性を強調しました。 APIは主要な攻撃ベクターになりつつあり、監視と予防制御の強化が必要です。ブラッドベリーは、トークンの使用を制限し、盗難を防止するメカニズムとして、所有証明(DPOP)を実証することを提唱しました。カレーは、「APIはより多くの制御が必要な新しいアクセスの高速道路になりつつあり、集合的により良い制御が必要です」と強調しました。

A Call to Action

行動への呼びかけ

This incident serves as a wake-up call for security leaders to prioritize security features in vendor selection and demand higher standards from their SaaS providers. By working together and sharing lessons learned, the cybersecurity community can raise the bar for security and create a more resilient ecosystem.

このインシデントは、セキュリティリーダーがベンダーの選択においてセキュリティ機能を優先し、SaaSプロバイダーにより高い基準を要求するためのモーニングコールとして機能します。サイバーセキュリティコミュニティは、協力して学んだ教訓を共有することで、セキュリティのために水準を上げ、より回復力のあるエコシステムを作成できます。

So, next time you're thinking about your company's security posture, remember the tale of Okta and Zscaler. It's a reminder that in the world of cybersecurity, a proactive approach and a strong defense are always in style, and maybe a little bit of luck. Stay safe out there, folks!

だから、次回あなたがあなたの会社のセキュリティの姿勢について考えているときは、OktaとZscalerの物語を覚えておいてください。サイバーセキュリティの世界では、積極的なアプローチと強力な防御が常にスタイリッシュであり、おそらく少し運が良くなることを思い出させてくれます。皆さん、安全を確保してください!

オリジナルソース:cyberscoop

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年08月22日 に掲載されたその他の記事