|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
针对漂移客户的最新供应链攻击强调了强大的安全措施的重要性。了解Okta和Zscaler如何以截然不同的结果导航相同的威胁。

The recent Salesloft Drift attacks sent ripples through the cybersecurity world, with Okta and Zscaler finding themselves in the crosshairs. While both companies faced the same threat, their experiences diverged dramatically, offering valuable lessons in cybersecurity strategy. In mid-August, a widespread data theft campaign occurred over a 10-day period.
最近的Salesloft Drift攻击使Okta和Zscaler在十字准线中找到自己的涟漪。尽管两家公司都面临着同样的威胁,但他们的经历却差异很大,为网络安全战略提供了宝贵的课程。在8月中旬,在10天的时间内发生了广泛的数据盗窃活动。
The Divergent Paths of Okta and Zscaler
Okta和Zscaler的不同路径
Okta's proactive security measures successfully thwarted the attack, preventing any lasting damage. Zscaler, however, wasn't as fortunate, experiencing unauthorized access to both customer and internal company data. This stark contrast underscores the critical role of a robust and layered security approach.
Okta的主动安全措施成功地挫败了这次袭击,从而阻止了任何持久的损害。但是,Zscaler并不幸运,他经历了未经授权的客户和内部公司数据的访问。这种鲜明的对比强调了强大而分层的安全方法的关键作用。
Understanding the Attack
了解攻击
The attack, attributed to the threat group UNC6395, exploited vulnerabilities in Salesloft's GitHub account and Drift's Amazon Web Services environment. This allowed the attackers to obtain OAuth tokens used by Drift customers, granting them access to sensitive data on integrated platforms.
归因于威胁组UNC6395的攻击利用了Salesloft的GitHub帐户和Drift的Amazon Web服务环境中的漏洞。这使攻击者能够获得漂流客户使用的OAuth代币,从而使他们可以在集成平台上访问敏感数据。
Okta's Proactive Defense
Okta的积极防御
Okta's success stemmed from its proactive monitoring and IP address restrictions for API calls. By identifying and blocking unauthorized access attempts from outside its configured IP range, Okta effectively neutralized the threat. David Bradbury, Okta's chief security officer, emphasized the importance of automating IP restriction implementation to make it more accessible for companies.
Okta的成功源于其主动监视和对API呼叫的IP地址限制。通过从其配置的IP范围之外识别和阻止未经授权的访问尝试,OKTA有效地消除了威胁。 Okta首席安全官David Bradbury强调了自动化IP限制实施以使公司更容易访问的重要性。
Zscaler's Experience and Lessons Learned
ZScaler的经验和经验教训
Despite having discontinued its use of Drift a month prior to the attack, Zscaler was still vulnerable due to an active OAuth token. The company faced the exposure of customer data, including names, email addresses, and product licensing information. Sam Curry, Zscaler's CISO, highlighted the critical need for limiting IP address ranges for API queries and rotating tokens more frequently.
尽管在袭击发生前一个月停止使用漂移,但由于活跃的OAuth代币,Zscaler仍然很容易受到伤害。公司面临客户数据的曝光率,包括名称,电子邮件地址和产品许可信息。 ZScaler的CISO Sam Curry强调了限制API查询的IP地址范围和更频繁地旋转令牌的关键需求。
The Mystery of Token Theft
令牌盗窃的奥秘
The exact method used to steal the OAuth tokens remains unclear. While Salesloft's investigation is ongoing, both Okta and Zscaler emphasize the need for stronger token security measures. As Bradbury noted, the internet's reliance on easily reusable tokens presents a significant vulnerability.
窃取OAuth代币的确切方法尚不清楚。尽管SalesLoft的调查正在进行中,但Okta和Zscaler都强调了对更强大的令牌安全措施的需求。正如布拉德伯里(Bradbury)所指出的那样,互联网对易于重复使用的令牌的依赖提出了一个重大脆弱性。
Collective Defense and the Future of API Security
集体防御与API安全的未来
Both Bradbury and Curry stressed the importance of collective defense and vendor accountability. APIs are becoming a major attack vector, requiring enhanced monitoring and preventative controls. Bradbury advocated for Demonstrating Proof of Possession (DPoP) as a mechanism to restrict token use and prevent theft. Curry emphasized that “APIs are becoming a new highway of access that we need more control over, and we need better control of collectively.”
布拉德伯里(Bradbury)和库里(Curry)都强调了集体辩护和供应商问责制的重要性。 API正在成为主要的攻击向量,需要增强监控和预防控制。布拉德伯里(Bradbury)主张证明拥有证明(DPOP)是限制令牌使用和防止盗窃的机制。库里强调说:“ API已成为我们需要更多控制权的新高速公路,我们需要更好地控制。”
A Call to Action
行动呼吁
This incident serves as a wake-up call for security leaders to prioritize security features in vendor selection and demand higher standards from their SaaS providers. By working together and sharing lessons learned, the cybersecurity community can raise the bar for security and create a more resilient ecosystem.
这项事件是使安全负责人呼吁供应商选择安全功能的优先级,并要求其SaaS提供商的更高标准。通过共同努力并分享学习的教训,网络安全社区可以提高安全性,并创建一个更具弹性的生态系统。
So, next time you're thinking about your company's security posture, remember the tale of Okta and Zscaler. It's a reminder that in the world of cybersecurity, a proactive approach and a strong defense are always in style, and maybe a little bit of luck. Stay safe out there, folks!
因此,下次您考虑公司的安全姿势时,请记住Okta和Zscaler的故事。这提醒人们,在网络安全的世界中,一种积极主动的方法和强大的防御方式总是时尚,也许是一点点运气。伙计们,保持安全!
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- XRP和比特币看到创新的继承特征和市场波动
- 2026-10-01 04:05:01
- Uphold 为 XRP 和比特币引入了加密继承,而市场数据显示,严重的空头挤压影响了主要加密货币。
-
-
-
-
-
-
-
-
































