Technology · 1 views
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.
Story Brief
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA.
Read full article on VenturebeatAI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Technology
Continue reading recent Technology coverage
- At G20, Big Tech and Global Leaders Can’t Escape AI’s Data Center ProblemContinue reading
- Here are some of REI’s best Labor Day sale dealsContinue reading
- NYC bans the use of generative AI tools in public schools for students through eighth gradeContinue reading
- Trump Administration Sides With OpenAI in New York Times Copyright LawsuitContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow