AI News HubAI News Hub
TodayNewsToolsIdeasTrends
TodayNewsToolsIdeasTrends

The AI brief, in your inbox

One email. The morning brief, new tools and where AI is heading — free.

AI News Hub — Daily AI news, tools, trends and ideasNews, tools, trends & ideas — updated twice daily at 5am & 4pmRSS
Back to News
AI

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

VentureBeat AI·September 2, 2026·1 min read
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

AI Summary

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs,…

From the source

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification

The full text couldn't be loaded here (the source may require a subscription).

View original at VentureBeat AI

Keep reading

AI can find your next apartment, but can it sell you a home? - Ynetnewsynetnews.com · 7h agoDeath of the essay: How AI is forcing universities to reinvent exams - AFRafr.com · 7h agoAI Use in the Job Market Is Creating an Infinite Doom LoopWired — AI · 7h agoIsrael takes its war on Palestine into the AI age - Al Jazeeraaljazeera.com · 7h ago
Was this useful?