Technophile NewsTechnophile News
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
What's On

Samsung Exynos 2600 SoC to Feature Heat Pass Block Component for Improved Cooling: Report

29 July 2025

Xiaomi 16 Ultra Tipped to Offer Continuous Optical Zoom Using a Shared CMOS Sensor

29 July 2025

The Real Demon Inside ChatGPT

29 July 2025

YouTube tells creators they can drop more F-bombs

29 July 2025

Redmi Note 15 Pro+ Could Be First Redmi Phone to Offer Satellite Communication

29 July 2025
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact Us
Tuesday, July 29
Facebook X (Twitter) Instagram YouTube
Technophile NewsTechnophile News
Demo
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
Technophile NewsTechnophile News
Home » Google Workspace is rolling out a security update to stop token stealing attacks
News

Google Workspace is rolling out a security update to stop token stealing attacks

By News Room29 July 20252 Mins Read
Facebook Twitter Pinterest LinkedIn Telegram Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Google Workspace is launching a new security measure to help prevent the same type of account takeover attack that impacted Linus Tech Tips. The feature, which is rolling out in beta for Chrome users on Windows, is designed to block bad actors from remotely stealing the cookies that keep you logged into your Workspace account.

Google calls the feature Device Bound Session Credentials (DBSC), and it does exactly what its name suggests: it protects users’ Workspace accounts by binding session cookies, the temporary files that websites use to remember user information, to their devices.

That makes it more difficult for attackers to carry out session token-stealing attacks, which often occur when a victim downloads information-stealing malware. From there, bad actors can exfiltrate a victim’s login credentials to a remote server, allowing them to sign into their account from another device or sell their credentials.

“Because this theft occurs after a user has logged in, it bypasses many existing account protections like 2FA [two-factor authentication],” Google spokesperson Ross Richendrfer tells The Verge. “Existing protections for this type of attack aren’t very mature, so it’s low-hanging fruit for attackers.”

In 2023, a bad actor took over the YouTube channel for Linus Tech Tips, along with two other Linus Media Group accounts, after an employee downloaded a fake sponsorship offer containing cookie-stealing malware. This week, YouTube issued a warning about a similar scam involving creators downloading phony brand deals. YouTube isn’t the only platform that we’ve seen impacted by cookie-stealing, either, as hackers hijacked several Chrome extensions last year, adding malware that exfiltrates session tokens for some websites.

Google says there’s been an “exponential rise” in cookie and authentication token theft over the past couple of years, and that this “trend has only intensified in 2025.” The company began working on DBSC last year, and said the verification platform Okta, as well as browsers like Microsoft Edge, have “expressed interest” in the concept. Along with DBSC, Google recommends that Workspace administrators enable passkeys as well, which is now available to over 11 million customers.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

The Real Demon Inside ChatGPT

29 July 2025

YouTube tells creators they can drop more F-bombs

29 July 2025

Age Verification Laws Send VPN Use Soaring—and Threaten the Open Internet

29 July 2025

The chaos and confusion of itch.io and Steam’s abrupt adult game ban

29 July 2025

This Smart Basketball Tracks Data About Every Shot. It Could Be Headed to the NBA

29 July 2025

Lovense was told its sex toy app leaked users’ emails and didn’t fix it

29 July 2025
Top Articles

iQOO Neo 10 Pro+ Confirmed to Debut This Month, Pre-Reservations Begin

8 May 2025157 Views

iQOO Z10 Turbo Pro – Price in India, Specifications (1st May 2025)

30 April 2025131 Views

iQOO Neo 10 Pro+ Battery, Charging Specifications Revealed; Will Be Equipped With 6,800mAh Battery

19 May 2025123 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Don't Miss

Age Verification Laws Send VPN Use Soaring—and Threaten the Open Internet

29 July 2025

After the United Kingdom’s Online Safety Act went into effect on Friday, requiring porn platforms…

The chaos and confusion of itch.io and Steam’s abrupt adult game ban

29 July 2025

Samsung Brings Faster One UI 8 Updates Using Google’s Trunk-Based Development Model: Report

29 July 2025

This Smart Basketball Tracks Data About Every Shot. It Could Be Headed to the NBA

29 July 2025
Technophile News
Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Technophile News. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.