Tag

Cloudsek

All articles tagged with #cloudsek

cybersecurity2 years ago

"Google Accounts Compromised: Hackers Bypass Passwords for Access"

A zero-day exploit in Google's cookie generation process, known as "MultiLogin," allows hackers to gain unauthorized access to Google accounts without needing passwords. The exploit enables session persistence, making it difficult for the true account owner to kick out the hacker with a password reset. Hackers have already incorporated the exploit into info-stealing malware, and various threat groups have rapidly adopted the technique. Google is yet to roll out a comprehensive solution, and affected users are advised to log out of all devices and browsers before resetting their passwords with sufficiently complex and unique ones.

cybersecurity2 years ago

"New Malware Bypasses Password Changes by Exploiting Google OAuth to Hijack Accounts"

CloudSEK researchers have reverse-engineered a zero-day exploit that leverages an undocumented Google OAuth endpoint, 'MultiLogin,' to regenerate persistent Google cookies even after password resets. Initially discovered by a developer named PRISMA, the exploit has been used by various malware, including Lumma Infostealer and White Snake, to maintain access to Google services. The exploit manipulates token:GAIA ID pairs extracted from Chrome's token_service table, allowing attackers to persistently exploit user accounts. Google has not yet confirmed the exploitation of this vulnerability.