Okta, a leading identity and access management provider, has released a critical security update for its Verify agent on Windows to address a vulnerability that could expose user passwords. Known as CVE-2024-9191, the flaw was discovered during routine penetration testing and affects versions 5.0.2 to 5.3.2 of the Windows-based Verify agent. The vulnerability is tied to Okta’s Device Access passwordless feature, allowing attackers with access to an already compromised device to retrieve passwords associated with Desktop MFA logins via the OktaDeviceAccessPipe. This issue specifically affects Windows users who utilize Okta Device Access passwordless logins. Users of other platforms or those relying solely on FastPass are unaffected. To mitigate this risk, Okta has released version 5.3.3 of the Verify agent for Windows and strongly advises all affected users to update to this version or later. The vulnerability was first introduced on April 17, 2024, in version 5.0.2, with an Early Access patch released on September 20, 2024, and a general availability update following on October 25, 2024. This incident highlights the importance of regular security audits and timely software updates to maintain cybersecurity. Okta also recommends that organizations strengthen their overall system defenses, as this vulnerability requires initial access to a compromised device. Maintaining strong device security and prompt patching are crucial to reducing potential exposure to such vulnerabilities.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...