{"id":50118,"date":"2023-01-13T18:03:04","date_gmt":"2023-01-13T18:03:04","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/circleci-lastpass-okta-slack-cyberattackers-target-enterprise-tools"},"modified":"2023-01-13T18:03:04","modified_gmt":"2023-01-13T18:03:04","slug":"circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/","title":{"rendered":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>In early January, development-pipeline service provider CircleCI warned users of a security breach, urging companies to immediately change the passwords, SSH keys, and other secrets stored on or managed by the platform.<\/p>\n<p>The <a href=\"https:\/\/www.darkreading.com\/dr-tech\/use-circleci-here-are-3-steps-you-need-to-take\" target=\"_blank\" rel=\"noopener\">attack on the DevOps service<\/a> left the company scrambling to determine the scope of the breach, limit attackers&#8217; ability to modify software projects, and determine which development secrets had been compromised. In the intervening days, the company rotated authentication tokens, changed configuration variables, worked with other providers to expire keys, and continued investigating the incident.<\/p>\n<p>&#8220;At this point, we are confident that there are no unauthorized actors active in our systems; however, out of an abundance of caution, we want to ensure that all customers take certain preventative measures to protect your data as well,&#8221; the company <a href=\"https:\/\/circleci.com\/blog\/january-4-2023-security-alert\/\" target=\"_blank\" rel=\"noopener\">stated in an advisory last week<\/a>.<\/p>\n<p>The <a href=\"https:\/\/www.darkreading.com\/application-security\/circleci-rotate-stored-secrets-asap\" target=\"_blank\" rel=\"noopener\">CircleCI compromise<\/a> is the latest incident that underscores attackers&#8217; increasing focus on fundamental enterprise services. Identity services, such as <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/ransomware-group-s-claim-that-it-hacked-okta-prompts-concerns-of-another-solarwinds\" target=\"_blank\" rel=\"noopener\">Okta<\/a> and <a href=\"https:\/\/www.darkreading.com\/application-security\/lastpass-discloses-second-breach-in-three-months\" target=\"_blank\" rel=\"noopener\">LastPass<\/a>, have disclosed compromises of their systems in the past year, while developer-focused services, such as <a href=\"https:\/\/www.darkreading.com\/cloud\/app-developers-increasingly-targeted-slack-devops-tools\" target=\"_blank\" rel=\"noopener\">Slack<\/a> and <a href=\"https:\/\/www.darkreading.com\/dr-tech\/lessons-from-the-github-cybersecurity-breach-protecting-the-most-sensitive-data\" target=\"_blank\" rel=\"noopener\">GitHub<\/a>, hastened to respond to successful attacks on their source code and infrastructure as well.<\/p>\n<p>The glut of&nbsp;attacks on core enterprise tools&nbsp;highlights the fact that companies should expect these types of&nbsp;providers to become regular targets in the future, says Lori MacVittie, a distinguished engineer and evangelist at cloud security firm F5.<\/p>\n<p>&#8220;As we rely more on services and software to automate everything from the development build to testing to deployment, these services become an attractive attack surface,&#8221; she says. &#8220;We don&#8217;t think of them as applications that attackers will focus on, but they are.&#8221;<\/p>\n<h2 class=\"regular-text\">Identity &amp; Developer Services Under Cyberattack<\/h2>\n<p>Attackers lately have focused on two major categories of services: identity and access management systems, and developer and application infrastructure. Both types of services underpin critical aspects of enterprise infrastructure.<\/p>\n<p>Identity is the glue that connects every part of an organization as well as connecting that organization to partners and customers, says Ben Smith, field CTO at NetWitness, a detection and response firm.<\/p>\n<p>&#8220;It doesn&#8217;t matter what product, what platform, you are leveraging &#8230; adversaries have recognized that the only thing better than an organization that specializes in authentication is an organization that specializes on authentication for other customers,&#8221; he says.<\/p>\n<p>Developer services and tools, meanwhile, have <a href=\"https:\/\/www.darkreading.com\/cloud\/app-developers-increasingly-targeted-slack-devops-tools\" target=\"_blank\" rel=\"noopener\">become another oft-attacked enterprise service<\/a>. In September, a threat actor <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/rockstar-games-confirms-grand-theft-auto-6-breach\" target=\"_blank\" rel=\"noopener\">gained access to the Slack channel<\/a> for the developers at Rockstar Games, for instance, downloading videos, screenshots, and code from the upcoming Grand Theft Auto 6 game. And on Jan. 9, <a href=\"https:\/\/slack.com\/intl\/en-au\/blog\/news\/slack-security-update\" target=\"_blank\" rel=\"noopener\">Slack said that it discovered<\/a> that &#8220;a limited number of Slack employee tokens were stolen and misused to gain access to our externally hosted GitHub repository.&#8221;<\/p>\n<p>Because identity and developer services often give access to a wide variety of corporate assets \u2014 from application services to operations to source code \u2014 compromising those services can be a skeleton key to the rest of the company, NetWitness&#8217;s Smith says.<\/p>\n<p>&#8220;They are very very attractive targets, which represent low-hanging fruit,&#8221; he says. &#8220;These are classic supply chain attacks \u2014 a plumbing attack, because the plumbing is not something that is visible on a daily basis.&#8221;<\/p>\n<h2 class=\"regular-text\">For Cyberdefense,&nbsp;Manage Secrets Wisely &amp; Establish Playbooks<\/h2>\n<p>Organizations should prepare for the worst and recognize that there are no simple ways to prevent the impact of such wide-ranging, impactful events, says Ben Lincoln, managing senior consultant at&nbsp;Bishop Fox.<\/p>\n<p>&#8220;There are ways to protect against this, but they do have some overhead,&#8221; he says. &#8220;So I can see developers being reluctant to implement them until it becomes evident that they are necessary.&#8221;<\/p>\n<p>Among the defensive tactics, Lincoln recommends the comprehensive management of secrets. Companies should be able to &#8220;push a button&#8221; and rotate all necessary password, keys, and sensitive configuration files, he says.<\/p>\n<p>&#8220;You need to limit exposure, but if there is a breach, you hopefully have a push button to rotate all those credentials immediately,&#8221; he says. &#8220;Companies should plan extensively in advance and have a process ready to go if the worst thing happens.&#8221;<\/p>\n<p>Organizations can also set traps for attackers. A variety of honeypot-like strategies allow security teams to have a high-fidelity warning that attackers may be in their network or on a service. Creating fake accounts and credentials, <a href=\"https:\/\/www.darkreading.com\/emerging-tech\/credential-canaries-create-minefield-for-attackers\" target=\"_blank\" rel=\"noopener\">so-called credential canaries<\/a>, can help detect when threat actors have access to sensitive assets.<\/p>\n<p>In all other ways, however, companies need to apply zero-trust principles to reduce their attack surface area of \u2014 not just machines, software, and services \u2014 but also operations, MacVittie says.<\/p>\n<p>&#8220;Traditionally, operations was hidden and safe behind a big moat [in the enterprise], so companies did not pay as much mind to them,&#8221; she says. &#8220;The way that applications and digital services are constructed today, operations involve a lot of app-to-app, machine-to-app identities, and attackers have started to realize that those identities are as valuable.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/circleci-lastpass-okta-slack-cyberattackers-target-enterprise-tools\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>High-profile software provider compromises in the past few months show that threat actors are actively targeting the services underpinning corporate infrastructure. Here&#8217;s what to do about it.Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/circleci-lastpass-okta-slack-cyberattackers-target-enterprise-tools\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-50118","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-13T18:03:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools\",\"datePublished\":\"2023-01-13T18:03:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/\"},\"wordCount\":828,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt3c09eacbb3db5bbf\\\/62a0be0b42b5552c7cb8c9d9\\\/Identity_Rex_Wholster_Alamy.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/\",\"name\":\"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt3c09eacbb3db5bbf\\\/62a0be0b42b5552c7cb8c9d9\\\/Identity_Rex_Wholster_Alamy.jpg\",\"datePublished\":\"2023-01-13T18:03:04+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt3c09eacbb3db5bbf\\\/62a0be0b42b5552c7cb8c9d9\\\/Identity_Rex_Wholster_Alamy.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt3c09eacbb3db5bbf\\\/62a0be0b42b5552c7cb8c9d9\\\/Identity_Rex_Wholster_Alamy.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/","og_locale":"en_US","og_type":"article","og_title":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-01-13T18:03:04+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools","datePublished":"2023-01-13T18:03:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/"},"wordCount":828,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/","url":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/","name":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg","datePublished":"2023-01-13T18:03:04+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt3c09eacbb3db5bbf\/62a0be0b42b5552c7cb8c9d9\/Identity_Rex_Wholster_Alamy.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/circleci-lastpass-okta-and-slack-cyberattackers-pivot-to-target-core-enterprise-tools\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"CircleCI, LastPass, Okta, and Slack: Cyberattackers Pivot to Target Core Enterprise Tools"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=50118"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50118\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=50118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=50118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=50118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}