Skip to content

company

Okta

Okta is an identity and access management company offering cloud-based single sign-on, multi-factor authentication, and identity governance for enterprises.

Known aliases

  • NASDAQ: OKTA
  • okta.com
  • Okta Cross App Access
  • Okta Inc.
  • Okta, Inc.
  • Okta SSO
  • Okta Threat Intelligence
  • Okta Ventures

Relationships

No evidence-backed relationships are recorded.

Current stories

build2 publishers

CloudWatch Omni opens incident investigation to staff without AWS console access

AWS's CloudWatch Omni, generally available since September 23, lets Okta and Entra ID users investigate incidents without AWS console access. CloudWatch dashboard sharing has let outsiders view prebuilt graphs since 2020, so what Omni adds is the investigation itself, one of the reasons teams paid for third-party platforms.

Publishers:dev.toinfoq.com

Reality

Evidence50
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence55
security1 publisher

Blueprint Alliance coalition aims to build agentic AI security standards around four key questions, lists six identity principles as governance guidance

Okta has gathered a dozen-odd technology companies into the Blueprint Alliance to write open security and interoperability standards for AI agents. The standards are still unwritten, and the six principles published so far are identity-management rules, the category Okta sells.

Publishers:scworld.com

Reality

Evidence45
Adoption10
Hype gap+25
Incentives75
Confidence40
security1 publisher

Australian Signals Directorate tells AI customers to guard their own keys and sessions

Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence50
security2 publishers

Okta's Blueprint Alliance gives buyers a six-point checklist for AI agent identity

Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.

Publishers:okta.comscworld.com

Reality

Evidence40
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence55
security5 publishers

ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence62
product5 publishers

CrowdStrike and Fortinet co-sign a letter that dates the security tooling they sell

More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.

Perspective Coverage

5 publishers
Builder
Builder 33%
Operator
Operator 42%
Investor
Investor 25%

Reality

Evidence70
Adoption20
Hype gap+35
Incentives80
Confidence65
invest3 publishers

Blackstone bets one part in 48,000 of its assets on a startup founded in 2025

Huskeys closed $27m five months after leaving stealth, with Blackstone leading what Globes calls the firm's first early-stage cybersecurity round. The cheque is worth about 0.002% of its assets.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 25%
Investor
Investor 50%

Reality

Evidence55
Adoption25
Hype gap+35
Incentives75
Confidence60
security9 publishers

McKesson's 8-K locates the stolen data inside third-party applications

The distributor found the intrusion on August 25, 2026, the same day ShinyHunters says its four-day exfiltration ended. It has not named the vendor applications involved, so customers are left scoping their own integrations.

Perspective Coverage

9 publishers
Builder
Builder 17%
Operator
Operator 66%
Investor
Investor 17%

Reality

Evidence50
Adoption
Insufficient
Hype gap+40
Incentives70
Confidence55

Earlier coverage

  1. Six OAuth steps run before an MCP client makes its first tool call

    Build · September 18, 2026 · 1 publisher

  2. Handing an agent the user's session token gives it every permission the user has

    Build · September 17, 2026 · 1 publisher

  3. Okta extends just-in-time privilege to AI agents and CI/CD pipelines

    Security · September 16, 2026 · 1 publisher

  4. Traefik Labs puts agent audit logs under witnesses the operator does not run

    Security · September 15, 2026 · 1 publisher

  5. CrowdStrike Stock Jumps 13.8% to Record High as AI-Safety Fears Boost Cybersecurity Sector

    Invest · September 14, 2026 · 3 publishers

  6. AgentCore's Consent portal absorbs the five pieces of session binding you used to host

    Build · September 14, 2026 · 1 publisher

  7. Flipping one deny to an allow broke the agent journal at record 3

    Build · September 13, 2026 · 1 publisher

  8. OpenAI, Anthropic and 100+ others urge governments to fund defenses against AI-enabled cyberattacks

    Invest · August 30, 2026 · 8 publishers

  9. Both banks Everest named in April traced the breach to a third-party vendor

    Security · September 10, 2026 · 1 publisher

  10. Stealer logs now carry AI session tokens that replay straight past MFA

    Security · September 9, 2026 · 1 publisher

  11. ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal

    Security · September 8, 2026 · 1 publisher

  12. Orphaned AI agents keep their access after the employee who created them moves on

    Product · September 7, 2026 · 1 publisher

  13. Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours

    Science · September 5, 2026 · 2 publishers

  14. Amid AI threats, qualified CISOs land seven-figure pay packages as cyber budgets rise 6%

    Invest · September 5, 2026 · 1 publisher

  15. Flare puts 46 percent of corporate stealer-log credentials on likely unmanaged devices

    Security · September 4, 2026 · 1 publisher

  16. An afternoon-built app keeps its database credential after the builder's SSO is revoked

    Build · September 1, 2026 · 1 publisher

  17. Rotation catches a stolen refresh token only when the server keeps the spent row

    Build · August 30, 2026 · 1 publisher

  18. Naming an AI agent moves the blame from its owner to the technology

    Leadership · August 28, 2026 · 1 publisher

  19. Rubrik's $1.66B ARR grew faster than its customer count

    Product · August 28, 2026 · 1 publisher

  20. Microsoft puts Defender Experts analysts on Palo Alto, AWS and Okta logs through Sentinel

    Security · August 27, 2026 · 1 publisher

  21. Nvidia's FY2028 guide reprices analysts' revenue models by about 18%

    Invest · August 27, 2026 · 1 publisher

  22. CrowdStrike cleared its own ARR guide by 17% while revenue beat by 2%

    Product · August 26, 2026 · 1 publisher

  23. Okta's partners touched all 20 of its biggest deals. Agent identity still has no number.

    Invest · August 27, 2026 · 1 publisher

  24. NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail

    Security · August 26, 2026 · 2 publishers

  25. The cheapest retrieval win this week sat at ingest, not in the agent loop

    Build · August 24, 2026 · 1 publisher

  26. A year without sprints: nine engineers, 36 services, and a WIP cap of eight graded B

    Build · August 22, 2026 · 1 publisher

  27. CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend

    Leadership · August 20, 2026 · 1 publisher

  28. The extortion call now comes from your help desk, and the fix is a procedure you own

    Leadership · August 19, 2026 · 1 publisher

  29. UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones

    Leadership · August 19, 2026 · 1 publisher

  30. AWS moves agent authorization out of the agent and into the plumbing

    Build · August 19, 2026 · 1 publisher

  31. Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call

    Security · August 19, 2026 · 1 publisher