How to Purge Google and Start Over – Part 1
ID: 6ac9d499-daee-5242-9944-0698937a6e65
STIX ID: report--6ac9d499-daee-5242-9944-0698937a6e65
Feed Name: Black Hills Infosec Blog
This is a first-person post describing a red-team engagement against a Google Workspace customer where the testers used CredSniper phishing and Google Calendar event injection to compromise accounts and bypass multi-factor authentication; Google’s SOC and the customer detected the activity, coordinated to suspend correlated accounts and revoke access, and the author outlines the operational impact, account disruptions, and concerns about opaque vendor de-platforming and pentest policy ambiguity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
