Stolen Claude session cookies can reach corporate Gmail through grant… | HappeningNow.news

Technology · 1 views

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

Source Story Brief Updated 2h 40m ago
Story intelligence Beta
Confidence Limited Single-outlet story
Views 1 Community interest
Brief read ~52 words

Story Brief

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA.

Read full article on Venturebeat

More from Technology

Continue reading recent Technology coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page