시가총액: $2.2043T 0.58%
거래량(24시간): $56.8553B 3.76%
  • 시가총액: $2.2043T 0.58%
  • 거래량(24시간): $56.8553B 3.76%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2043T 0.58%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

Okta, Zscaler 및 드리프트 공격 : 두 가지 보안 전략 이야기

2025/10/06 18:00

드리프트 고객을 대상으로하는 최근의 공급망 공격은 강력한 보안 조치의 중요성을 강조합니다. Okta와 Zscaler가 어떻게 다른 결과로 동일한 위협을 탐색했는지 알아보십시오.

Okta, Zscaler 및 드리프트 공격 : 두 가지 보안 전략 이야기

The recent Salesloft Drift attacks sent ripples through the cybersecurity world, with Okta and Zscaler finding themselves in the crosshairs. While both companies faced the same threat, their experiences diverged dramatically, offering valuable lessons in cybersecurity strategy. In mid-August, a widespread data theft campaign occurred over a 10-day period.

최근 Salesloft 드리프트 공격은 사이버 보안 세계를 통해 잔물결을 보냈으며 Okta와 Zscaler는 십자선에서 자신을 발견했습니다. 두 회사 모두 같은 위협에 직면했지만 그들의 경험은 극적으로 크게 분기되어 사이버 보안 전략에서 귀중한 교훈을 제공했습니다. 8 월 중순, 광범위한 데이터 도난 캠페인이 10 일 동안 발생했습니다.

The Divergent Paths of Okta and Zscaler

Okta와 Zscaler의 발산 경로

Okta's proactive security measures successfully thwarted the attack, preventing any lasting damage. Zscaler, however, wasn't as fortunate, experiencing unauthorized access to both customer and internal company data. This stark contrast underscores the critical role of a robust and layered security approach.

Okta의 사전 보안 조치는 공격을 성공적으로 방해하여 지속적인 피해를 방지했습니다. 그러나 Zscaler는 운이 좋지 않았으며 고객 및 내부 회사 데이터 모두에 대한 무단 액세스를 경험했습니다. 이 대비는 강력하고 계층화 된 보안 접근법의 중요한 역할을 강조합니다.

Understanding the Attack

공격 이해

The attack, attributed to the threat group UNC6395, exploited vulnerabilities in Salesloft's GitHub account and Drift's Amazon Web Services environment. This allowed the attackers to obtain OAuth tokens used by Drift customers, granting them access to sensitive data on integrated platforms.

위협 그룹 UNC6395에 기인 한이 공격은 Salesloft의 GitHub 계정 및 Drift의 Amazon Web Services 환경에서 취약점을 악용했습니다. 이를 통해 공격자는 드리프트 고객이 사용하는 OAUTH 토큰을 얻을 수있어 통합 플랫폼에서 민감한 데이터에 액세스 할 수있었습니다.

Okta's Proactive Defense

Okta의 사전 방어

Okta's success stemmed from its proactive monitoring and IP address restrictions for API calls. By identifying and blocking unauthorized access attempts from outside its configured IP range, Okta effectively neutralized the threat. David Bradbury, Okta's chief security officer, emphasized the importance of automating IP restriction implementation to make it more accessible for companies.

Okta의 성공은 API 통화에 대한 사전 모니터링 및 IP 주소 제한에서 비롯되었습니다. Okta는 구성된 IP 범위 외부에서 무단 액세스 시도를 식별하고 차단함으로써 위협을 효과적으로 중화시켰다. Okta의 최고 보안 책임자 인 David Bradbury는 IP 제한 구현 자동화의 중요성을 강조하여 회사가보다 쉽게 ​​액세스 할 수 있도록했습니다.

Zscaler's Experience and Lessons Learned

Zscaler의 경험과 교훈

Despite having discontinued its use of Drift a month prior to the attack, Zscaler was still vulnerable due to an active OAuth token. The company faced the exposure of customer data, including names, email addresses, and product licensing information. Sam Curry, Zscaler's CISO, highlighted the critical need for limiting IP address ranges for API queries and rotating tokens more frequently.

공격 전 한 달 전에 드리프트 사용을 중단 했음에도 불구하고 Zscaler는 활발한 OAUTH 토큰으로 인해 여전히 취약했습니다. 회사는 이름, 이메일 주소 및 제품 라이센스 정보를 포함하여 고객 데이터의 노출에 직면했습니다. ZSCALER의 CISO 인 Sam Curry는 API 쿼리의 IP 주소 범위와 회전 토큰을 더 자주 제한 해야하는 중요한 요구를 강조했습니다.

The Mystery of Token Theft

토큰 도난의 신비

The exact method used to steal the OAuth tokens remains unclear. While Salesloft's investigation is ongoing, both Okta and Zscaler emphasize the need for stronger token security measures. As Bradbury noted, the internet's reliance on easily reusable tokens presents a significant vulnerability.

OAUTH 토큰을 훔치는 데 사용되는 정확한 방법은 여전히 ​​불분명합니다. Salesloft의 조사가 진행 중이지만 Okta와 Zscaler는 더 강력한 토큰 보안 조치의 필요성을 강조합니다. Bradbury가 지적했듯이, 인터넷의 재사용 가능한 토큰에 대한 인터넷의 의존은 상당한 취약성을 나타냅니다.

Collective Defense and the Future of API Security

집단 방어와 API 보안의 미래

Both Bradbury and Curry stressed the importance of collective defense and vendor accountability. APIs are becoming a major attack vector, requiring enhanced monitoring and preventative controls. Bradbury advocated for Demonstrating Proof of Possession (DPoP) as a mechanism to restrict token use and prevent theft. Curry emphasized that “APIs are becoming a new highway of access that we need more control over, and we need better control of collectively.”

Bradbury와 Curry는 모두 집단 방어 및 공급 업체 책임의 중요성을 강조했습니다. API는 주요 공격 벡터가되어 향상된 모니터링 및 예방 제어가 필요합니다. Bradbury는 토큰 사용을 제한하고 도난을 방지하는 메커니즘으로 Propess (DPOP)를 시연하기로 옹호했습니다. Curry는“API는 우리가 더 많은 통제가 필요한 새로운 접근 고속도로가되고 있으며 집합 적으로 더 나은 통제가 필요하다”고 강조했다.

A Call to Action

행동 유도 문안

This incident serves as a wake-up call for security leaders to prioritize security features in vendor selection and demand higher standards from their SaaS providers. By working together and sharing lessons learned, the cybersecurity community can raise the bar for security and create a more resilient ecosystem.

이 사건은 보안 리더가 공급 업체 선택의 보안 기능을 우선 순위로 정하고 SAAS 제공 업체로부터 높은 표준을 요구하는 모닝콜 역할을합니다. 사이버 보안 커뮤니티는 함께 일하고 배운 교훈을 공유함으로써 보안의 기준을 높이고보다 탄력적 인 생태계를 만들 수 있습니다.

So, next time you're thinking about your company's security posture, remember the tale of Okta and Zscaler. It's a reminder that in the world of cybersecurity, a proactive approach and a strong defense are always in style, and maybe a little bit of luck. Stay safe out there, folks!

따라서 다음에 회사의 보안 자세에 대해 생각하면 Okta와 Zscaler의 이야기를 기억하십시오. 사이버 보안의 세계에서는 사전 예방 접근 방식과 강력한 방어가 항상 스타일이며 아마도 약간 운이 좋다는 것을 상기시켜줍니다. 안전하게 지내세요!

원본 소스:cyberscoop

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年08月11日 에 게재된 다른 기사