Habr•August 26, 2026•🇷🇺Translated from Russian

Password Reset Fails to Evict Attackers: What Persists in Compromised Email Accounts

Users often discover unauthorized access to their email, change the password, enable two-factor authentication, and assume the threat is over. Within days or weeks, however, messages continue to be read and forwarded, revealing that the attacker never relied on the password alone.

Password verification occurs only once during login. After that, the service issues a persistent credential such as a session cookie in the browser or a refresh token in a mail client. These tokens allow continued access without re-entering the password, and a password change does not automatically revoke them.

Attackers commonly retain the following footholds:

  • Active sessions – browser cookies stolen by infostealers that bypass password knowledge entirely.
  • Application tokens – OAuth grants issued to third-party apps that continue working after the main password reset.
  • App passwords – legacy credentials created for older clients that ignore two-factor authentication and survive password changes.
  • Mail rules and forwarding – automatic redirection of incoming messages to attacker-controlled addresses or rules that archive replies during business-email-compromise schemes.
  • Recovery data – substituted backup email addresses, phone numbers, or recovery codes that let the attacker regain entry later.
  • Delegation – explicit sharing permissions granted inside the mail service that password changes do not affect.

Google users should review myaccount.google.com/device-activity, myaccount.google.com/permissions, and myaccount.google.com/apppasswords, then check Gmail settings for forwarding, delegation, and filters. Yandex offers equivalent controls under the security section of id.yandex.ru. Microsoft accounts are managed at account.microsoft.com/security.

In corporate Microsoft 365 environments, administrators can run Revoke-MgUserSignInSession via Microsoft Graph to terminate refresh tokens, although short-lived access tokens may remain valid for roughly one hour. Additional PowerShell queries detect forwarding rules and OAuth consents with scopes such as Mail.Read and offline_access.

The correct remediation order is: first revoke all sessions and tokens, then change the password to a completely new value, review and reset multi-factor methods, update recovery information, and finally audit rules and connected applications. Performing these steps in the wrong sequence allows the attacker to re-establish persistence before the account is fully secured.

Related articles

AntiMalware•Other

RemoveMacAI Utility Appears on GitHub to Disable Apple Intelligence and Free Disk Space on macOS

A new open-source tool called RemoveMacAI has been released on GitHub, allowing macOS users to fully disable Apple Intelligence features and remove associated AI models from their systems. The utility addresses the lack of a single toggle in macOS 27 for turning off generative AI capabilities while also reclaiming storage space occupied by downloaded models. It supports Apple silicon devices and works by leveraging Apple's own system services rather than directly modifying protected directories. Users can selectively disable components such as Siri, Writing Tools, Genmoji, Image Playground, ChatGPT integration, smart replies, photo cleanup, and Xcode predictive code completion. The tool also installs a configuration profile that prevents models from being redownloaded automatically. Reversion is possible via the removemacai revert command, though this comes at the cost of losing access to certain Apple Intelligence-powered functions in third-party apps and Shortcuts. The project is licensed under MIT and leaves Dictation untouched as it is managed separately.

Habr•Other

Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02

The article explains how to leverage the Issuer Security Domain mechanisms on GlobalPlatform cards to establish secure channels for applet personalization without implementing custom ECDH-based key exchange. It addresses limitations of prior approaches that lacked authentication and required extensive PKI support. The solution uses SCP02 with specific security levels such as C_MAC and C_DECRYPTION to protect commands that store AES-128 keys and personal data on the card. Detailed code walkthroughs cover the applet constructor, process method, mutual authentication via SecureChannel.processSecurity, and unwrap operations for decrypting and verifying APDUs. Practical testing on NXP Java Cards demonstrates installation via FunGP library scripts that allow configurable security levels during mutual authentication. The implementation ensures that secret key updates enforce C_DECRYPTION while personal data writes accept C_MAC, with encrypted reads performed using AES-CBC.

AntiMalware•Other

IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women

Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.

Securitylab•Other

Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems

Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.