OpenSSL HollowByte: A DoS Hiding in 11 Bytes
The Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL.

Okta Security Research feed covering identity threats, detection rules, and workforce-identity advisories.
Watch items
Showing the 20 most recent items, newest first. Each row links to the official advisory.
20 rows · sorted newest first
Operations viewThe Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL.
Okta and Datadog have collaborated to enhance the Out-of-the-Box (OotB) detection capabilities of Datadog’s Cloud SIEM by including rules from the Okta Security Detection Catalog. These rules have been engineered to enable the identification of identity-related threats with minimal configuration.
Okta Verify has a neat trick under the hood that can help you identify the use of personal AI assistants and other "not just yet" software.
Version 1.1 of the Okta Security Technical Implementation Guide (STIG) provides U.S. government agencies additional hardening recommendations related to network security and non-human identities.
Okta and its customers are benefitting from "pooled" security audits.
Temporary Access Codes provide an opportunity to constrain the ability of help desk staff to reset user passwords and MFA factors.
Read on for Okta’s response to React2Shell (CVE-2025-55182) and to learn more about actions required by developers.
Take a peek inside the latest AitM phishing kit.
Russia-linked campaign targets hospitality and vacation rental providers.
The Auth0 Customer Detection Catalog is an open-source repository of detection rules designed to help the security teams at Auth0 customers to proactively identify and respond to security threats.
The world needs a better way to manage app-to-app access.
ClickFix campaigns exploit user trust and problem-solving instincts to bypass conventional security measures.
Okta has completed another pooled audit, leading the industry by transforming traditional one-to-one assessments into a collaborative, industry-first approach. This new model not only streamlines the audit experience but delivers impact: 90% of participating customers reported significantly greater confidence in demonstrating compliance.
The days when the name of your childhood best friend or your first car model provided enough assurance to validate your identity are long gone. That’s where Caller Verify can help.
ISO/IEC 27001 is a globally recognized security standard. This blog introduces a new Factsheet that provides guidance on how Okta can support organizations of any size in achieving or maintaining compliance to the ISO/IEC 27001:2022 standard.
A one-year progress update on Okta's commitment to the CISA Secure by Design Pledge.
Introducing the Okta Security Detection Catalog, a repository of detection queries designed to help Okta customers.
This is the third iteration in our blog series. This blog article explores how the Okta Security Customer Audit further enhances the Customer Trust function, driving even greater transparency and confidence in our security practices to meet our customers' regulatory and compliance requirements.
Okta recently announced our partnership with DISA, which has resulted in the release of the Okta Identity as a Service (IDaaS) Security Technical Implementation Guide (STIG) an an effort to secure baselines for the industry.
This blog article provides a brief overview of the DORA regulation, outlines how Okta can support compliance adherence, and introduces our new Factsheet, a helpful resource for satisfying DORA's regulated requirements.
| Alert | Exposure | Status | Published | Source |
|---|---|---|---|---|
OpenSSL HollowByte: A DoS Hiding in 11 BytesThe Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL. | Watch | watch | Jul 15, 2026, 8:00 PM | Vendor advisoryOpen source |
Datadog and Okta Combine for New Customer DetectionsOkta and Datadog have collaborated to enhance the Out-of-the-Box (OotB) detection capabilities of Datadog’s Cloud SIEM by including rules from the Okta Security Detection Catalog. These rules have been engineered to enable the identification of identity-related threats with minimal configuration. | Watch | watch | Mar 7, 2026, 6:00 AM | Vendor advisoryOpen source |
Detecting OpenClaw at Sign-InOkta Verify has a neat trick under the hood that can help you identify the use of personal AI assistants and other "not just yet" software. | Watch | watch | Feb 10, 2026, 6:00 PM | Vendor advisoryOpen source |
Okta Hardening Guide Updated to Secure Non-Human IdentitiesVersion 1.1 of the Okta Security Technical Implementation Guide (STIG) provides U.S. government agencies additional hardening recommendations related to network security and non-human identities. | Watch | watch | Feb 3, 2026, 2:00 AM | Vendor advisoryOpen source |
Okta Pooled Security Audits: a One-Year RetrospectiveOkta and its customers are benefitting from "pooled" security audits. | Watch | watch | Jan 11, 2026, 6:00 PM | Vendor advisoryOpen source |
Account Recovery, without Password ResetsTemporary Access Codes provide an opportunity to constrain the ability of help desk staff to reset user passwords and MFA factors. | Watch | watch | Dec 9, 2025, 6:00 PM | Vendor advisoryOpen source |
Okta’s Response to React2ShellRead on for Okta’s response to React2Shell (CVE-2025-55182) and to learn more about actions required by developers. | CVE-2025-55182 Elevated | watch | Dec 4, 2025, 6:00 PM | Vendor advisoryOpen source |
Uncloaking VoidProxy: a Novel and Evasive Phishing-as-a-Service FrameworkTake a peek inside the latest AitM phishing kit. | Watch | watch | Sep 10, 2025, 7:00 PM | Vendor advisoryOpen source |
Attackers Target Hotelier Accounts in Malvertising and Phishing CampaignRussia-linked campaign targets hospitality and vacation rental providers. | Watch | watch | Aug 28, 2025, 7:00 PM | Vendor advisoryOpen source |
Using Auth0 Logs for Proactive Threat DetectionThe Auth0 Customer Detection Catalog is an open-source repository of detection rules designed to help the security teams at Auth0 customers to proactively identify and respond to security threats. | Watch | watch | Aug 18, 2025, 7:00 PM | Vendor advisoryOpen source |
Controlling Cross-App Data Sprawl in Google WorkspaceThe world needs a better way to manage app-to-app access. | Watch | watch | Jul 30, 2025, 7:00 PM | Vendor advisoryOpen source |
How this ClickFix campaign leads to Redline StealerClickFix campaigns exploit user trust and problem-solving instincts to bypass conventional security measures. | Watch | watch | Jul 2, 2025, 7:00 PM | Vendor advisoryOpen source |
Paving the Path: Pooled Audits with Okta SecurityOkta has completed another pooled audit, leading the industry by transforming traditional one-to-one assessments into a collaborative, industry-first approach. This new model not only streamlines the audit experience but delivers impact: 90% of participating customers reported significantly greater confidence in demonstrating compliance. | Watch | watch | Jun 24, 2025, 7:00 PM | Vendor advisoryOpen source |
Building Confidence in Support Comms with Caller Verify at OktaThe days when the name of your childhood best friend or your first car model provided enough assurance to validate your identity are long gone. That’s where Caller Verify can help. | Watch | watch | Jun 17, 2025, 7:00 PM | Vendor advisoryOpen source |
Enabling ISO/IEC 27001:2022 Compliance with OktaISO/IEC 27001 is a globally recognized security standard. This blog introduces a new Factsheet that provides guidance on how Okta can support organizations of any size in achieving or maintaining compliance to the ISO/IEC 27001:2022 standard. | Watch | watch | Jun 3, 2025, 7:00 PM | Vendor advisoryOpen source |
Okta’s Secure by Design Pledge - One Year OnA one-year progress update on Okta's commitment to the CISA Secure by Design Pledge. | Watch | watch | May 21, 2025, 7:00 PM | Vendor advisoryOpen source |
Leveraging Okta System Logs for Proactive Threat DetectionIntroducing the Okta Security Detection Catalog, a repository of detection queries designed to help Okta customers. | Watch | watch | May 19, 2025, 7:00 PM | Vendor advisoryOpen source |
Enhancing Customer Trust Through a Comprehensive Audit ProgramThis is the third iteration in our blog series. This blog article explores how the Okta Security Customer Audit further enhances the Customer Trust function, driving even greater transparency and confidence in our security practices to meet our customers' regulatory and compliance requirements. | Watch | watch | May 13, 2025, 7:00 PM | Vendor advisoryOpen source |
Okta's new Security Technical Implementation Guide (STIG)Okta recently announced our partnership with DISA, which has resulted in the release of the Okta Identity as a Service (IDaaS) Security Technical Implementation Guide (STIG) an an effort to secure baselines for the industry. | Watch | watch | May 8, 2025, 7:00 PM | Vendor advisoryOpen source |
A Guide to DORA Compliance with OktaThis blog article provides a brief overview of the DORA regulation, outlines how Okta can support compliance adherence, and introduces our new Factsheet, a helpful resource for satisfying DORA's regulated requirements. | Watch | watch | May 6, 2025, 7:00 PM | Vendor advisoryOpen source |
Vendor watch hub
The Oktawatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
At a glance
Tracked
Active
Featured
Unique CVEs
Most recent entry
Jul 15, 2026, 8:00 PM
Feed refreshes daily · 5:15 a.m. Central
Sources·Okta Security Research RSS
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
ITECS response pathways
These pathways connect the vendor watch feed into service-owner resources that already carry commercial authority.
Use the cybersecurity services pathway when this vendor alert needs an ITECS-managed response plan.
Connect the vendor watch page to broader managed detection, response, and governance planning.
Translate current watch items into a faster risk snapshot and prioritized remediation plan.
Return to the hub for cross-vendor prioritization, live filtering, and broader MSP threat context.
Vendor watch FAQ
It is the Okta-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
Use it to confirm whether current Okta issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Yes. ITECS can help map Okta advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.