why do the hackers disclose the hack though? why not keep it silent and abuse more
seems pretty easy to hack a SaaS anyway. just need to phish an engineering employee account. often they have superuser access to debug customer issues
seems pretty easy to hack a SaaS anyway. just need to phish an engineering employee account. often they have superuser access to debug customer issues
> yes we know the URL has a email address. the account is suspended - we dont care
Not saying this looks good and really not trying to defend Okta, but a user account being terminated isn't proof that Okta knew about it.