Hackers have found a way to access Google without needing their password.

A new vulnerability gives hackers persistent access to Google services, even after a user's password is reset. The vulnerability was analyzed by security firm CloudSEK and reported by The Independent. The issue also came to light when a hacker posted related information on a Telegram channel in October 2023.
Read more: loanDepot: Recent breach was a ransomware attack
The Independent magazine report states that Google accounts can be compromised due to a vulnerability in cookies used by websites and browsers. These cookies are used to track users and improve their performance. In addition, Google’s authentication cookies help users save their login details and log in automatically. However, hackers have found a way to bypass two-factor authentication and retrieve these cookies.
It highlights the need for continuous monitoring of both technical vulnerabilities and human intelligence resources to address emerging cyber threats. At the same time, Google is upgrading its defenses in Google Chrome to protect users from malware, taking measures to protect compromised accounts that are detected.

See also: Capital Health: Victim of LockBit ransomware attack
Users are advised to take ongoing security measures, such as enabling Enhanced Safe Browsing in Chrome, to protect themselves from receiving information via phishing emails and malware.
Source: livemint.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
