Cybercrime

Cybercrime – Hackers found new Ways to access Google accounts without a password.

Nowadays cybercrime is increasing and hackers are finding new ways to hack accounts without having passwords.

Thank you for reading this post, don't forget to subscribe!

What is cybercrime?

Cybercrime is defined as any unlawful behaviour involving computers, networks, or digital devices. Fraud, identity theft, data breaches, computer infections, and scams are examples of harmful acts.

How does cybercrime happen?

Researchers identified a flaw that allows hackers to gain access to people’s Google accounts without having to know their passwords.

Hacking gangs are already actively testing a new type of malware that uses third-party cookies to gain unauthorized access to people’s private data, according to the cybersecurity firm CloudSEK.

The issue was discovered in October 2023, when a hacker mentioned it on a Telegram channel.
PRISMA, a developer, discovered a significant attack in October 2023 that allowed the establishment of permanent Google cookies via token manipulation. “This exploit allows continuous access to Google services even after a user’s password has been reset,” stated Pavan Karthick M, a CloudSEK threat intelligence researcher.

Video credit – YouTube channel Bitten Tech

The researchers traced the exploit’s origins back to an undocumented Google Oauth endpoint called “MultiLogin.”
The report outlined how accounts may be stolen due to a weakness in cookies, which websites and browsers use to track users and improve their efficiency and usefulness.

Google authentication cookies allow users to access their accounts without repeatedly entering their login information; however, hackers discovered a way to remove these cookies to overcome two-factor authentication.

Steps taken by Google about the account hack which is one type of cybercrime-

The Chrome web browser is currently cracking down on third-party cookies, according to the Independent.
We frequently enhance our defences against such approaches and protect users who become infected with malware. “In this case, Google has taken action to secure any compromised accounts discovered,” Google said.

What should follow in that case-

“Users should continually take steps to remove any malware from their computer, and we recommend turning on Enhanced Safe Browsing in Chrome to protect against phishing and malware downloads,” it added.

Further, Karthick M mentioned that this highlights the necessity for continuous monitoring of technical vulnerabilities and human intelligence sources to stay ahead of emerging cyber threats. (IANS).

Conclusion:

In this era of cybercrime, we should be aware of everything. We should keep track of our password changes and other things especially where we are allowing cookies for any sites.

Source credit: Shillong Times.