Companies

Okta

Follow the latest coverage, related explainers and connected technology stories.

Latest coverage

CN
Why Should the Agent Gateway Not Be the First Layer for Protecting AI Agents?

Why Should the Agent Gateway Not Be the First Layer for Protecting AI Agents?

Nik Kale argues that securing AI agents should be built as a six-layer chain that begins with inventorying agents and defining their identities and authorization context before reaching policy enforcement through runtime gateways. He proposes a practical framework for testing readiness, with a focus on limited permissions, attributable logs, and a comprehensive shutdown path.

CN
McKesson Discloses Breach After ShinyHunters Claims to Have Stolen Patient Data

McKesson Discloses Breach After ShinyHunters Claims to Have Stolen Patient Data

McKesson announced that third-party applications were accessed without authorization and data was extracted, while the ShinyHunters group claims to have stolen approximately 284 million patient-related records. Neither the company nor BleepingComputer has verified the type of data stolen or the number of individuals affected.

CN
More Than 100 Technology Companies Call for a Collective Response to the Risks of AI-Supported Cyberattacks

More Than 100 Technology Companies Call for a Collective Response to the Risks of AI-Supported Cyberattacks

OpenAI, Anthropic, Google and Microsoft, along with cybersecurity companies and financial institutions, signed an open letter calling on the public and private sectors to develop new defenses against more sophisticated AI-led cyberattacks. The letter proposes partnerships and higher security standards, but does not specify concrete implementation commitments or particular joint solutions.

CN
ReliaQuest: Impersonation Attack and Data Theft Failed to Bypass Device Trust Controls

ReliaQuest: Impersonation Attack and Data Theft Failed to Bypass Device Trust Controls

ReliaQuest confirmed that one of its employees entered their details on a fake SSO page after being targeted with impersonation calls, giving the attacker temporary read-only access to the identity dashboard. The company said device trust controls prevented access to applications, systems, and customer data, while the ShinyHunters group claimed responsibility for the attack without final confirmation from ReliaQuest.

CN
Google Makes Device-Bound Session Credentials Available to Chrome Users on Windows

Google Makes Device-Bound Session Credentials Available to Chrome Users on Windows

Google has announced the public availability of Device Bound Session Credentials on Chrome 146 for Windows users, with plans to expand the technology to macOS in a future release. The technology links login sessions to encryption keys stored in the device’s hardware, making stolen cookies unusable.