{"id":99951,"date":"2022-04-20T04:48:20","date_gmt":"2022-04-20T06:48:20","guid":{"rendered":"https:\/\/teknomers.com\/fr\/okta-affirme-que-la-violation-de-la-securite-par-les-pirates-lapsus-na-touche-que-deux-de-ses-clients\/"},"modified":"2022-04-20T04:48:27","modified_gmt":"2022-04-20T06:48:27","slug":"okta-affirme-que-la-violation-de-la-securite-par-les-pirates-lapsus-na-touche-que-deux-de-ses-clients","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/okta-affirme-que-la-violation-de-la-securite-par-les-pirates-lapsus-na-touche-que-deux-de-ses-clients\/","title":{"rendered":"Okta affirme que la violation de la s\u00e9curit\u00e9 par les pirates Lapsus $ n&#8217;a touch\u00e9 que deux de ses clients"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Le fournisseur de gestion des identit\u00e9s et des acc\u00e8s Okta a d\u00e9clar\u00e9 mardi avoir conclu son enqu\u00eate sur la violation d&#8217;un fournisseur tiers fin janvier 2022 par le gang d&#8217;extorqueurs LAPSUS$.<\/p>\n<p>D\u00e9clarant que &#8220;l&#8217;impact de l&#8217;incident \u00e9tait nettement inf\u00e9rieur \u00e0 l&#8217;impact potentiel maximum&#8221; que la soci\u00e9t\u00e9 avait pr\u00e9c\u00e9demment partag\u00e9 le mois dernier, Okta <a rel=\"nofollow noopener\" href=\"https:\/\/www.okta.com\/blog\/2022\/04\/okta-concludes-its-investigation-into-the-january-2022-compromise\/\" target=\"_blank\">mentionn\u00e9<\/a> l&#8217;intrusion n&#8217;a touch\u00e9 que deux clients locataires, contre 366 initialement suppos\u00e9s.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701000_960_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>L&#8217;\u00e9v\u00e9nement de s\u00e9curit\u00e9 a eu lieu le 21 janvier lorsque le groupe de piratage LAPSUS$ a obtenu un acc\u00e8s \u00e0 distance non autoris\u00e9 \u00e0 un poste de travail appartenant \u00e0 un ing\u00e9nieur de support Sitel.  Mais cela n&#8217;est devenu public que pr\u00e8s de deux mois plus tard, lorsque l&#8217;adversaire a publi\u00e9 des captures d&#8217;\u00e9cran des syst\u00e8mes internes d&#8217;Okta sur sa cha\u00eene Telegram.<\/p>\n<p>En plus d&#8217;acc\u00e9der \u00e0 deux locataires clients actifs dans l&#8217;application SuperUser &#8211; utilis\u00e9e pour effectuer des fonctions de gestion de base &#8211; le groupe de pirates aurait consult\u00e9 des informations suppl\u00e9mentaires limit\u00e9es dans d&#8217;autres applications comme Slack et Jira, corroborant les rapports pr\u00e9c\u00e9dents.<\/p>\n<p>&#8220;Le contr\u00f4le a dur\u00e9 25 minutes cons\u00e9cutives le 21 janvier 2022&#8221;, a d\u00e9clar\u00e9 David Bradbury, responsable de la s\u00e9curit\u00e9 d&#8217;Okta.  &#8220;L&#8217;acteur de la menace n&#8217;a pas pu effectuer avec succ\u00e8s les modifications de configuration, les r\u00e9initialisations de MFA ou de mot de passe, ou les \u00e9v\u00e9nements d'&#8221;emprunt d&#8217;identit\u00e9&#8221; du support client.&#8221;<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;L&#8217;acteur de la menace n&#8217;a pas pu s&#8217;authentifier directement sur les comptes Okta&#8221;, a ajout\u00e9 Bradbury.<\/p>\n<p>Okta, qui a \u00e9t\u00e9 critiqu\u00e9 pour sa divulgation tardive et sa gestion de l&#8217;incident, a d\u00e9clar\u00e9 qu&#8217;il avait mis fin \u00e0 sa relation avec Sitel et qu&#8217;il apportait des modifications \u00e0 son outil de support client pour &#8220;limiter de mani\u00e8re restrictive les informations qu&#8217;un ing\u00e9nieur de support technique peut voir&#8221;.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/okta-says-security-breach-by-lapsus.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le fournisseur de gestion des identit\u00e9s et des acc\u00e8s Okta a d\u00e9clar\u00e9 mardi avoir conclu son enqu\u00eate sur la violation d&#8217;un fournisseur tiers fin janvier 2022 par le gang d&#8217;extorqueurs LAPSUS$. D\u00e9clarant que &#8220;l&#8217;impact de l&#8217;incident \u00e9tait nettement inf\u00e9rieur \u00e0 l&#8217;impact potentiel maximum&#8221; que la soci\u00e9t\u00e9 avait pr\u00e9c\u00e9demment partag\u00e9 le mois dernier, Okta mentionn\u00e9 l&#8217;intrusion [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":99952,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[7178,8004,4168,4158,4165,4161,245,4157,4159,4171,4170,33682,65,4167,4160,4163,4162,33459,164,4394,1835,4172,4169,269,6727,899,4166,4164],"class_list":["post-99951","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affirme","tag-clients","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-deux","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-lapsus","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-okta","tag-par","tag-pirates","tag-securite","tag-securite-informatique","tag-securite-internet","tag-ses","tag-touche","tag-violation","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/99951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=99951"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/99951\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/99952"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=99951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=99951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=99951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}