Dec. 29, 2023, 6:20 p.m. |

BankInfoSecurity.com RSS Syndication www.bankinfosecurity.com

Google OAuth2 Vulnerability Being Actively Abused by Attackers, Researchers Warn
A previously undiscovered critical exploit can allow threat actors to gain persistent, unauthorized access to Google services and connected accounts even after users have changed their passwords, cybersecurity researchers warn. They said the flaw enables hackers to manipulate the OAuth 2 protocol.

access accounts attackers connected critical cybersecurity exploit flaw google hackers hijacking info info-stealing malware malware oauth oauth2 passwords persistent protocol researchers services session session hijacking stealing threat threat actors unauthorized access vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States