Researchers at Authomize have identified four security risks in the identity and access management (IAM) platform Okta, which could expose personal identifiable information (PII), allow for account takeovers, or destroy organizational data. The issues include password leakage, unencrypted data sharing, unsafe default configurations, and identity log spoofing. It was noted these findings didn’t classify as vulnerabilities, with Okta stating its features function as intended. However, the researchers insist that independent security measures ought to be proactively implemented in relation to IAM tools.

Breach of F5 requires “emergency action” from BIG-IP users, feds warn
Thousands of networks—many of them operated by the US government and Fortune 500 companies—face an “imminent threat” of being breached by a nation-state hacking group