0
Deep & Emerging Tech·September 2, 2026·1 min read

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Share

Stolen Claude cookies jumping into corporate Gmail via ungoverned grants shows how SaaS‑to‑SaaS auth can bypass your IdP and MFA entirely. This week, audit OAuth scopes from AI tools into core apps and treat self‑serve, card‑billed AI accounts as shadow IT with direct access to your comms layer.