Skip to content
Threat Feed

Vendor

Okta

59 briefs RSS
low advisory

Unusual Spike in Concurrent Active Sessions by a User

An Elastic machine learning rule detects an unusual spike in concurrent active Okta sessions initiated by a user, indicating potential adversary abuse of valid credentials for privilege escalation or persistence through the execution of multiple privileged operations.

Okta machine-learning anomaly-detection privilege-escalation persistence cloud-security
3t
low advisory

Unusual Process Detected for Privileged Commands by a User on Linux

Elastic's machine learning rule identifies anomalous execution of privileged commands by a user on Linux systems, indicative of potential privilege escalation or misuse of valid accounts.

Privileged Access Detection integration +6 linux machine-learning privileged-access privilege-escalation anomaly-detection
2t
low advisory

Spike in User Account Management Events

Elastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.

Privileged Access Detection integration +7 privileged-access-detection machine-learning anomaly-detection windows account-management privilege-escalation persistence
5t updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +511 roundup
11c 354i updated
high advisory

Okta User Risk Threshold Exceeded via Aggregated Suspicious Activities

This correlation identifies when a user exceeds a risk threshold based on multiple suspicious Okta activities by aggregating risk events from 'Suspicious Okta Activity,' 'Okta Account Takeover,' and 'Okta MFA Exhaustion' analytic stories, highlighting potentially compromised user accounts exhibiting multiple TTPs that could lead to unauthorized access, privilege escalation, or persistence.

Okta +3 account-takeover risk-framework
2r 2t
high threat

UNC6671 BlackFile Vishing Extortion Campaign Targeting Microsoft 365 and Okta

UNC6671, operating under the "BlackFile" brand, conducts a sophisticated extortion campaign targeting organizations through voice phishing (vishing) and single sign-on (SSO) compromise, using adversary-in-the-middle (AiTM) techniques to bypass MFA and exfiltrate sensitive corporate data.

Microsoft 365 +5 UNC6671 vishing extortion aitm credential-theft data-exfiltration sso
2r 8t 5i
low advisory

Unusual Spike in Okta User Lifecycle Management Change Events

A machine learning job has identified an unusual spike in Okta user lifecycle management change events, indicating potential privileged access activity where threat actors may manipulate user accounts to gain higher access rights or persist within the environment.

Okta privileged-access user-lifecycle
2r 4t
high advisory

Okta Admin Console Unusual Behavior Detection

This brief details detection of anomalous activity within the Okta Admin Console, potentially indicating privilege escalation, persistence, defense evasion, or initial access attempts by malicious actors.

Okta Identity Engine okta identity privilege-escalation persistence defense-evasion initial-access
2r 4t
high advisory

Okta Password Entered in AlternateID Field

Okta logs may contain user passwords if a user mistakenly enters their password into the username field during login, potentially exposing credentials in logs.

Okta Identity Engine attack.credential-access attack.t1552 okta password-leak
2r 1t
medium advisory

Okta Policy Rule Modification or Deletion

An Okta policy rule was modified or deleted, potentially weakening security controls.

Okta identity policy attack.impact
2r 1t
medium advisory

Okta Initial Access via Proxy

Detection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.

Okta initial-access proxy
2r 1t
medium advisory

Okta Network Zone Deactivation or Deletion

An Okta network zone was deactivated or deleted, potentially indicating malicious activity aimed at bypassing security controls.

Okta Identity Engine okta network-zone impact
2r 1t
medium advisory

Okta Password Spray Attempt Detection

Detection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.

Okta credential-access password-spraying
2r 1t
medium advisory

Okta Identity Provider Creation Detected

An adversary may create a rogue identity provider within Okta to establish persistence and potentially escalate privileges by impersonating legitimate users or bypassing multi-factor authentication.

Okta identityprovider persistence
3r 2t
low advisory

Okta User Account Created

Detection of new user account creation in Okta, which could indicate malicious activity related to credential access.

Okta identity user-creation credential-access
2r 1t
medium advisory

Okta Security Threat Detected

This alert detects when Okta's ThreatInsight identifies a security threat within an Okta environment, potentially indicating command and control activity.

Okta identity threat-detection attack.command-and-control
2r 1t
medium advisory

Okta Admin Role Assignment Creation

Detection of new admin role assignments in Okta, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta identity privilege-escalation persistence
2r 1t
high advisory

Auth0.js SDK Improper Permission Checking Vulnerability

The Auth0.js SDK versions 8.11.0 to 9.32.0 improperly returns user profile information when provided a crafted invalid ID token, potentially bypassing access controls relying on Auth0 Actions.

auth0.js SDK auth0 sdk vulnerability authentication
2r 1t
medium advisory

Okta End-User Reports Suspicious Account Activity

An Okta end-user reports potentially suspicious activity on their account, indicating possible compromise or unauthorized access.

Okta identity suspicious-activity
2r 1t
high advisory

Okta User Logins from Multiple Cities Within 24 Hours

This analytic identifies instances where the same Okta user logs in from different cities within a 24-hour period, potentially indicating a compromised account and leading to account takeovers and data breaches.

Okta account-takeover identity
2r 2t
low advisory

Okta Group Lifecycle Change Spike Indicating Privilege Escalation

A machine learning job has identified an unusual spike in Okta group lifecycle change events, indicating potential privilege escalation activity, where adversaries may be altering group structures to escalate privileges, maintain persistence, or facilitate lateral movement within an organization’s identity management system.

Okta privileged-access group-lifecycle
2r 4t
low advisory

Unusual Source IP for Okta Privileged Operations Detected

A machine learning job has identified a user performing privileged operations in Okta from an uncommon source IP, indicating potential privileged access activity indicative of account compromise or privilege escalation.

Okta privileged-access machine-learning
2r 3t
high advisory

Okta MFA Disabled by User

Detection of Okta multi-factor authentication (MFA) being disabled by a user account, potentially indicating malicious activity or account compromise and leading to unauthorized access.

Okta Identity Cloud okta mfa account-takeover persistence
2r 1t
medium advisory

Okta Session Hijacking via Multiple Device Token Hashes

Detection of multiple device token hashes and source IPs for a single Okta session, indicating potential session hijacking and unauthorized access to Okta resources.

Okta session-hijacking credential-access
2r 2t
low advisory

Empty GitHub Page Threat Brief

This brief analyzes a GitHub page which appears to be a placeholder or error, containing no actionable threat intelligence data.

Okta initial-access placeholder
1r 1t
high advisory

Okta Alerts Following Unusual Proxy Authentication

Attackers use proxy infrastructure to mask their origin when using stolen Okta credentials, and this rule correlates the first occurrence of an Okta user session started via a proxy with subsequent Okta security alerts for the same user.

Okta identity cloud initial-access
2r 1t
high advisory

Okta User Reports Suspicious Activity

A user reporting a suspicious login attempt via Okta's reporting mechanism indicates potential unauthorized access and possible account compromise.

Okta Identity Management okta account-takeover t1078.001
2r 1t
medium advisory

Okta Unauthorized Application Access Attempt

This brief describes a detection for unauthorized application access attempts within an Okta environment, indicating a potential security breach or misconfiguration.

Okta attack.impact threat-type platform
3r
medium advisory

Okta Unauthorized Access to Application

Anomalous activity indicating a user is attempting to access Okta applications they have not been assigned, potentially leading to data exposure or service disruption.

Okta Identity Cloud okta unauthorized-access identity
2r 2t
high advisory

Okta ThreatInsight Detection of Credential Access Attempts

Okta ThreatInsight detected events indicating password spraying, login failures, and high counts of unknown user login attempts, potentially leading to unauthorized access and credential compromise.

Okta Identity Cloud okta credential-access password-spraying account-takeover
2r 1t
high advisory

Okta Suspicious Session Cookie Use

This detection identifies the suspicious use of a session cookie by detecting multiple client values (IP, User Agent, etc.) changing for the same Device Token associated with a specific user, potentially indicating credential access and unauthorized account access.

Okta Identity Cloud okta session-cookie credential-access
2r 1t
medium advisory

Okta Successful Single Factor Authentication Attempt

Successful single-factor authentication events against the Okta Dashboard for accounts without Multi-Factor Authentication (MFA) enabled, potentially indicating account takeover attempts.

Okta Identity Cloud okta single-factor authentication account takeover
2r 3t 2i
high advisory

Okta Successful Login After Credential Attack

Detection of successful Okta logins following a potential credential compromise, indicating successful account takeover.

Okta Identity and Access Management okta credential_access account_takeover
2r 1t
low advisory

Okta Policy Modification or Deletion Detected

An Okta policy was modified or deleted, potentially indicating unauthorized changes to security configurations within the Okta identity management platform by a malicious actor or insider.

Okta Identity Cloud identity okta policy attack.impact
2r 1t
high advisory

Okta Multiple Users Failing Authentication From Single IP

Multiple users failing to authenticate from a single IP address within a short timeframe in Okta indicates potential brute-force or password spraying attacks, leading to unauthorized access and data breaches.

Okta brute-force password-spraying credential-access
2r 1t
high threat

Okta Multiple Failed MFA Requests Indicate Potential MFA Bypass Attempt

An adversary may attempt to bypass MFA by bombarding a user with repeated authentication requests, potentially leading to unauthorized access and system compromise.

Okta Lapsus$ +6 mfa credential-access mfa-bypass
2r 1t
high advisory

Okta Multiple Account Lockouts Indicative of Password Spraying

Multiple Okta accounts locked out within a 5-minute period, detected via aggregated user.account.lock events, may indicate a password spraying attack leading to potential account takeovers.

Okta password-spraying account-lockout
2r 1t
medium advisory

Okta MFA Reset or Deactivation Attempt

An attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.

Okta Identity Cloud okta mfa credential-access persistence
2r 1t
high advisory

Okta Identity Provider Lifecycle Modifications

Detection of modifications to Okta Identity Provider (IDP) lifecycle events, such as creation, activation, deactivation, and deletion, which can indicate potential security breaches or misconfigurations.

Okta Identity Cloud okta idp lifecycle identity
2r 1t
medium advisory

Okta Group Privilege Change Spike via ML Detection

A machine learning job has identified an unusual spike in Okta group privilege change events, indicating potential privileged access activity where attackers might be elevating privileges by adding themselves or compromised accounts to high-privilege groups, enabling further access or persistence.

Okta privilege-escalation machine-learning
2r 4t
low advisory

Okta Group Application Assignment Spike Indicates Privilege Escalation

A machine learning job identified a spike in Okta group application assignment changes, potentially indicating threat actors escalating privileges, maintaining persistence, or moving laterally by assigning applications to groups.

Okta privileged-access privilege-escalation
2r 4t
high advisory

Okta FastPass Phishing Attempt Detection

Okta FastPass detected and prevented a phishing attempt, indicating a user was likely targeted with a credential harvesting attack.

Okta phishing fastpass
2r 1t
medium advisory

Okta Authentication Failed During MFA Challenge

Detection of failed authentication attempts during Okta MFA challenges, potentially indicating compromised credentials and attempts to bypass MFA.

Okta Identity Cloud okta mfa authentication account-takeover
2r 3t
medium advisory

Okta Application Sign-On Policy Modified or Deleted

Attackers may modify or delete Okta application sign-on policies to weaken security controls, potentially leading to unauthorized access and data breaches.

Okta identity policy-tampering
2r 1t
medium advisory

Okta Application Modified or Deleted

Detects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.

Okta application-security identity-management
2r 1t
medium advisory

Okta API Token Revoked

Detection of Okta API token revocation events, indicating potential unauthorized access or compromise.

Okta api token revocation identity
2r 1t
high advisory

Okta API Token Creation Detection

Detection of new Okta API token creation, potentially indicating account compromise or unauthorized access leading to persistence and administrative control.

Okta Identity Cloud okta api_token account_takeover persistence
2r 1t
medium advisory

Okta API Token Creation

Detection of Okta API token creation events which can indicate malicious persistence activity.

Okta Identity Cloud persistence okta
2r 1t
high advisory

Geographic Improbable Location Detection

Detection of user logins originating from geographically distant locations within a short timeframe, indicative of potential Remote Employment Fraud or compromised credentials.

Workday +6 remote-employment-fraud credential-compromise okta
2r 1t
medium advisory

Detection of Okta Administrator Role Assignment to User or Group

Detects the assignment of an Okta administrator role to a user or group, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta privilege-escalation persistence
2r 1t
high advisory

Okta User Risk Threshold Exceeded

A user exceeding a risk threshold in Okta indicates a potential account compromise, leveraging Enterprise Security's Risk Framework by aggregating risk events from multiple suspicious Okta activities, which may lead to unauthorized access and privilege escalation.

Okta account-takeover risk-framework
2r 3t
high advisory

Okta User Session Start via Anonymizing Proxy Service

Detection of Okta user sessions initiated through anonymizing proxy services, potentially indicating malicious activity or attempts to evade security controls.

Okta identity proxy defense-evasion
2r 1t
medium advisory

Okta User Account Lockout Detection

Detection of an Okta user account lockout, which may indicate brute-force attempts or other malicious activity targeting user accounts.

Okta identity account-lockout
2r 1t
low advisory

Okta Privileged Operations from Unusual Host Name Detected

A machine learning job detected a user performing privileged operations in Okta from an uncommon device, potentially indicating a compromised account or insider threat attempting privilege escalation.

Okta privileged-access-detection machine-learning privilege-escalation
2r 2t
medium advisory

Okta New Device Enrollment Detection

Detection of new device enrollments in Okta, potentially indicating account takeover or unauthorized access by an adversary.

Okta Identity Cloud okta account-takeover persistence cloud
2r 1t
low advisory

Okta Group Membership Spike Detection

A machine learning job has identified an unusual spike in Okta group membership events, indicating potential privileged access activity where attackers or malicious insiders might be adding accounts to privileged groups to escalate their access, potentially leading to unauthorized actions or data breaches.

Okta privileged-access privilege-escalation
2r 4t
medium advisory

Okta Credential Stuffing Attempt Detection

This brief focuses on detecting credential stuffing attacks against Okta, characterized by multiple failed login attempts from a single source, potentially indicating automated attempts to compromise user accounts.

Okta credential-stuffing account-takeover
2r 1t
medium advisory

Masquerading Business Application Installers

Attackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.

Elastic Defend +22 masquerading defense-evasion initial-access malware windows
2r 4t
high advisory

Okta Device Token Brute-Force Attempt

An adversary attempts to compromise Okta accounts by brute-forcing device tokens to bypass multi-factor authentication (MFA) and gain unauthorized access.

Okta brute-force credential-access mfa-bypass
2r 1t