<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exploit New token hack in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Exploit-New-token-hack/m-p/2099#M1654</link>
    <description>&lt;P&gt;Just an awareness piece&lt;/P&gt;&lt;P&gt;&lt;A href="https://cybernews.com/news/google-accounts-vulnerable-to-new-token-hack/" target="_blank" rel="noopener"&gt;https://cybernews.com/news/google-accounts-vulnerable-to-new-token-hack/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/malware-abuses-google-oauth-endpoint-to-revive-cookies-hijack-accounts/#google_vignette" target="_blank" rel="noopener"&gt;https://www.bleepingcomputer.com/news/security/malware-abuses-google-oauth-endpoint-to-revive-cookies-hijack-accounts/#google_vignette&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Dec 2023 21:46:11 GMT</pubDate>
    <dc:creator>Rick2025</dc:creator>
    <dc:date>2023-12-31T21:46:11Z</dc:date>
    <item>
      <title>Exploit New token hack</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Exploit-New-token-hack/m-p/2099#M1654</link>
      <description>&lt;P&gt;Just an awareness piece&lt;/P&gt;&lt;P&gt;&lt;A href="https://cybernews.com/news/google-accounts-vulnerable-to-new-token-hack/" target="_blank" rel="noopener"&gt;https://cybernews.com/news/google-accounts-vulnerable-to-new-token-hack/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/malware-abuses-google-oauth-endpoint-to-revive-cookies-hijack-accounts/#google_vignette" target="_blank" rel="noopener"&gt;https://www.bleepingcomputer.com/news/security/malware-abuses-google-oauth-endpoint-to-revive-cookies-hijack-accounts/#google_vignette&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Dec 2023 21:46:11 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Exploit-New-token-hack/m-p/2099#M1654</guid>
      <dc:creator>Rick2025</dc:creator>
      <dc:date>2023-12-31T21:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Exploit New token hack</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Exploit-New-token-hack/m-p/2101#M1655</link>
      <description>&lt;P&gt;Thanks, Rick.&lt;/P&gt;&lt;P&gt;Like most malware, it relies on first having access to to the user's computer, so having a proper endpoint security system, or a Chromebook (without rogue extensions!), is still as important as ever.&lt;/P&gt;&lt;P&gt;And it's a bit annoying that neither article clearly explains how to break the "hack" if affected.&lt;/P&gt;&lt;P&gt;One of the comments on the Bleeping article does, and is fairly easy to understand.&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Interim Remediation Steps:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;While we await a comprehensive solution from Google, users can take immediate action to safeguard against this exploit. If you suspect your account may have been compromised, or as a general precaution, sign out of all browser profiles to invalidate the current session tokens. Following this, reset your password and sign back in to generate new tokens. This is especially crucial for users whose tokens and GAIA IDs might have been exfiltrated. Resetting your password effectively disrupts unauthorized access by invalidating the old tokens which the infostealers rely on, thus providing a crucial barrier to the continuation of their exploit."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 04:42:38 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Exploit-New-token-hack/m-p/2101#M1655</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2024-01-01T04:42:38Z</dc:date>
    </item>
  </channel>
</rss>

