Technology · 20 views
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.
Summary
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Technology
Continue reading recent Technology coverage
- Microsoft floats rules for its own AI models as industry debates a slowdownContinue reading
- Hear how AI can engineer nature’s comeback at TechCrunch Disrupt 2026Continue reading
- Will GTA 6's Ultimate Edition be worth the extra cost? Here's what it'll come withContinue reading
- Perfect-10 GitLab bug under attack days after patch landsContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow