Design Flaw in Domain-Wide Delegation Could Leave Google Workspace Vulnerable for Takeover, Says Cybersecurity Company Hunters
by cyberwire from NextBigFuture.com on (#6GQFW)
Boston, Massachusetts, November 28th, 2023, Cyberwire A severe design flaw in Google Workspace's domain-wide delegation feature discovered by threat hunting experts from Hunters' Team Axon, can allow attackers to misuse existing delegations, enabling privilege escalation and unauthorized access to Workspace APIs without Super Admin privileges. Such exploitation could result in theft of emails from Gmail, ...