Skip to main content

Yahoo is warning users over state-sponsored cookie-forging attacks

Yahoo’s security woes continue with the company sending out a fresh warning to users over hacked accounts at the hands of allegedly state-sponsored actors.

In an email to users, Yahoo said it has identified evidence of cookie-forging attacks on some accounts, which would allow attackers to access an account without re-entering a password. The email was only sent to accounts that Yahoo believes have been affected by these intrusion attempts so we don’t know how many people have been impacted.

Recommended Videos

“Our outside forensic experts have been investigating the creation of forged cookies that could allow an intruder to access users’ accounts without a password,” the email reads. “Based on the ongoing investigation, we believe a forged cookie may have been used in 2015 or 2016 to access your account.”

It is believed that hackers obtained Yahoo’s source code for creating cookies. The company’s forensics team has invalidated any corrupted cookies it found.

It’s not clear what evidence Yahoo has to suggest these cookie forging attempts were state-sponsored. However, Yahoo has been the victim of at least two major hacks that were disclosed in the last few months for which it pointed the finger at possible hackers acting on behalf of a government.

The numerous data breaches at the web firm included 500 million accounts compromised in 2014 and up to 1 billion accounts compromised in 2013. But it wasn’t until last year that these mega breaches — as they’ve been dubbed — came to light. Yahoo is now currently under investigation by the Securities and Exchange Commission over why it waited years before disclosing the details of the hacks.

The security blunders could be costly for Yahoo as Verizon, its purchaser, has since sought a price tag reduction between $250 million and $350 million (off the original $4.83 billion offer), as it was unaware of these breaches when the offer was made.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
AMD’s RDNA 4 may surprise us in more ways than one
AMD RX 7800 XT and RX 7700 XT graphics cards.

Thanks to all the leaks, I thought I knew what to expect with AMD's upcoming RDNA 4. It turns out I may have been wrong on more than one account.

The latest leaks reveal that AMD's upcoming best graphics card may not be called the RX 8800 XT, as most leakers predicted, but will instead be referred to as the  RX 9070 XT. In addition, the first leaked benchmark of the GPU gives us a glimpse into the kind of performance we can expect, which could turn out to be a bit of a letdown.

Read more
This futuristic mechanical keyboard will set you back an eye-watering $1,600
Hands typing on The Icebreaker keyboard.

I've complained plenty about how some of the best gaming keyboards are too expensive, from the Razer Black Widow V4 75% to the Wooting 80HE, but nothing comes remotely close to The Icebreaker. Announced nearly a year ago by Serene Industries, The Icebreaker is unlike any keyboard I've ever seen -- and it's priced accordingly at $1,600. Plus shipping, of course.

What could justify such an extravagant price? Aluminum, it turns out. The keyboard is constructed of one single block of 6061 aluminum in what Serene Industries calls an "unorthodox wedge form." As if that wasn't enough metal, the keycaps are also made of aluminum, and Serene says they include "about 800" micro-perforations that allow the LED backlight of the keyboard to shine through.

Read more
Google one-ups Microsoft by making chats easier to transfer
Google Spaces in Google Chat on a MacBook.

In a recent blog post, Google announced that it is making it easier for admins to migrate from Microsoft Teams to Google Chat to reduce downtime. Admins can easily do this within the Google Chat migration menu and connect to opposing Microsoft accounts to transfer Teams data.

Google gave step-by-step instructions for admins on how to transfer the messages. Admins need to connect to their Microsoft account and upload a CSV of the Teams from where they transfer the messages. From there, it requires just entering a starting date for messages to be migrated from Teams and clicking Star migration. Once it's complete, it'll make the migrated space, messages, and conversation data available to Google Workspace users.

Read more