Google Workspace and the Google Cloud Platform targeted in novel attacks

Bitdefender has warned of its discovery of a new attack methodology that threat actors may use against victims who are using Google Workspace and the Google Cloud Platform, reports The Hacker News. In its report, the company demonstrated how hackers that have already gained unauthorized access to a local machine by some other means can take advantage of how Google Credential Provider for Windows works, which is to use the local privileged service account Google Accounts and ID Administration to verify users’ credentials and then store a refresh token that eliminates the need for re-authentication.

Source: SC Magazine

 


Date:

Categorie(s):