I think it’s important to provide candid, even critical, feedback on topics of national security. But I don’t ever want to imply that the various govt agencies and the people at them are not genuinely amazing human beings trying really hard to do good in often hard situations
No the White House notice isn’t really actionable for cybersecurity professionals and yes many are already tired, but it’s still significant and cybersecurity personnel are not necessarily the core audience. I’m not sure they had many better options than to publish what they did.
#Okta:
1. Share the information internally.
2. Collect and retain related logs.
3. Hunt logs for bad.
4. Rotate Okta privileged passwords.
5. Move on unless Okta reaches out to you that you are involved. Adjust DFIR to their context.
That’s about all you can do right now.
You know you’re a nerd when you’re excited your team uses Slack so you can DM yourself all the links to things you want/need to read instead of keeping 7,000 tabs open which I will also likely do.