April 20, 2023

GhostToken Vulnerability in Google's Cloud Platform Could Allow Permanent Infection of User Accounts

Researchers at Astrix Security have discovered a security vulnerability in Google's Cloud Platform (GCP) called "GhostToken" that could have allowed cyber attackers to conceal a malicious application inside a victim's Google account, leaving it in a permanent state of undetectable infection. The malicious app could enable attackers to read the victim's Gmail account, access files in Google Drive and Photos, view their Google Calendar, and track their location via Google Maps. This information could be used to craft convincing impersonation and phishing attacks, or even to put the victim in physical danger. Google has since patched the vulnerability.

Read the full article here.

All Posts

Let's talk

We’re here to help! Submit your information or call the office on +44 (0)1243 670 854 and a member of our team would be happy to help.

Who are Cybaverse?
How can we support your business?
Why work with us?