SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • July 29, 2025
  • Rss Fetcher

Google Workspace is launching a new security measure to help prevent the same type of account takeover attack that impacted Linus Tech Tips. The feature, which is rolling out in beta for Chrome users on Windows, is designed to block bad actors from remotely stealing the cookies that keep you logged into your Workspace account.

Google calls the feature Device Bound Session Credentials (DBSC), and it does exactly what its name suggests: it protects users’ Workspace accounts by binding session cookies, the temporary files that websites use to remember user information, to their devices.

That makes it more difficult for attackers to carry out session token-stealing attacks, which often occur when a victim downloads information-stealing malware. From there, bad actors can exfiltrate a victim’s login credentials to a remote server, allowing them to sign into their account from another device or sell their credentials.

“Because this theft occurs after a user has logged in, it bypasses many existing account protections like 2FA [two-factor authentication],” Google spokesperson Ross Richendrfer tells The Verge. “Existing protections for this type of attack aren’t very mature, so it’s low-hanging fruit for attackers.”

In 2023, a bad actor took over the YouTube channel for Linus Tech Tips, along with two other Linus Media Group accounts, after an employee downloaded a fake sponsorship offer file containing cookie-stealing malware. This week, YouTube issued a warning about a similar scam involving creators downloading phony brand deals. YouTube isn’t the only platform that we’ve seen impacted by cookie-stealing, either, as hackers hijacked several Chrome extensions last year, adding malware that exfiltrates session tokens for some websites.

Google says there’s been an “exponential rise” in cookie and authentication token theft over the past couple of years, and that this “trend has only intensified in 2025.” The company began working on DBSC last year, and said the verification platform Okta, as well as browsers like Microsoft Edge, have “expressed interest” in the concept. Along with DBSC, Google recommends that Workspace administrators enable passkeys as well, which is now available to over 11 million customers.

Previous Post
Next Post

Recent Posts

  • Can Python or Ruby Feel First-Class in the Browser?
  • PlayerZero raises $15M to prevent AI agents from shipping buggy code 
  • Ready or not, age verification is rolling out across the internet
  • Minnesota activates National Guard as cyberattack on Saint Paul disrupts public services
  • Skechers is making kids’ shoes with a hidden AirTag compartment

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.