• Crooks Bypassed Google’s Email Verification to Create Workspace Accounts

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Crooks Bypassed Google’s Email Verification to Create Workspace Accounts

    Author
    Topic
    #2691259

    https://krebsonsecurity.com/2024/07/crooks-bypassed-googles-email-verification-to-create-workspace-accounts-access-3rd-party-services/

    Google says it recently fixed an authentication weakness that allowed crooks to circumvent the email verification required to create a Google Workspace account, and leverage that to impersonate a domain holder at third-party services that allow logins through Google’s “Sign in with Google” feature.

    “In the last few weeks, we identified a small-scale abuse campaign whereby bad actors circumvented the email verification step in our account creation flow for Email Verified (EV) Google Workspace accounts using a specially constructed request,” the notice from Google read. “These EV users could then be used to gain access to third-party applications using ‘Sign In with Google’.”..

    On July 12, a number of domains tied to cryptocurrency businesses were hijacked from Squarespace users who hadn’t yet set up their Squarespace accounts. Squarespace has since published a statement blaming the domain hijacks on “a weakness related to OAuth logins”, which Squarespace said it fixed within hours…

    • This topic was modified 10 months, 1 week ago by Alex5723.
    1 user thanked author for this post.
    Reply To: Crooks Bypassed Google’s Email Verification to Create Workspace Accounts

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: