InfoSec, tweeting and tooting when time allows. Dipping toes in mastodon at [email protected] - Founding (former) editor of SRSLY RISKY BIZ newsletter.
Come work with us @okta ! We're looking for a new member of Okta's Threat Intelligence team. This role is one in which if you have a good idea that fits our mission, you can run with it. Plus, we're nice people. 😀 North Korean IT workers need not apply. https://t.co/nGQQyrGRPM
Over several weeks, @okta tested OpenClaw with various AI models to see how agents handle API keys, OAuth tokens and credentials. Agents can't be trusted, and it's easy to talk them into skirting their guardrails. Don't let agents see secrets! More here: https://t.co/WVLzdO3Wvq
I recently joined @reckless on @DecoderPod to discuss the “SaaSpocalypse,” the future of software, and why the identity layer for AI agents could become the biggest category in cyber. Really enjoyed this conversation: https://t.co/afZ84f2ymM
A browser extension promised security. In reality, it was a Trojan horse for your crypto.
We tracked the extension, mapped the infrastructure and pulled the plug.
Full breakdown of the takedown: https://t.co/KuAuOdWUyx
Your star hire might be a DPRK agent. 🇰🇵 @Okta reveals how state actors use stolen LinkedIn IDs, AI-generated faces, and forged git commits to bypass HR. Verify identities before they're on your payroll! #opentowork https://t.co/vUS3m8GMeD
Google disrupted IPIDEA, a major residential proxy network. Our data confirms a sharp drop in their active IPs following the action. 📉
Protect your Okta org today: block IPIDEA and residential proxies with dynamic network zones https://t.co/dR0hjjZ5ac
Still tracking the bad packets, now powered by Okta log data! Top ASNs used in recent signup fraud attacks:
• 212238
• 16276
• 44477
• 26548
• 200373
• 137409
• 214483
• 13213
• 397368
Cross App Access (XAA) is now the #MCP authorization extension: ‘Enterprise-Managed Authorization’.
Proud @okta played a role in establishing this new protocol to secure AI. https://t.co/VAPtPvRszi
We’ve introduced passkeys as a simple and secure option for people to sign in to their myGov account.
Your account will be most secure when you create a passkey and turn off your password as a sign in option.
To find out more watch this video, or visit: https://t.co/PkKDE3Krdi
Check out our very own CPO, @clcsampaio, being interviewed on @riskybusiness about Identity and Fine Grained Authorization!
🎧 Listen to the full episode here: https://t.co/2kXxwKTsqo