{"ok":true,"trend":{"id":764193,"platform":"mastodon","region":"global","key":"any # infosec or # google folks know of an authoritative checklist of every way someone can persist in access a # google","title":"Any # infosec or # Google folks know of an authoritative checklist of every way someone can persist in access a # Google","url":"https://infosec.exchange/@deFractal/117372667071524411","first_seen":"2026-10-02T18:22:08.837386Z","last_seen":"2026-10-02T18:22:08.837386Z","last_rank":8,"peak_rank":8,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.89109375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A security practitioner is asking the infosec community for an authoritative checklist covering every way an attacker can maintain access to a Google account after a phishing incident. The account owner fell for a Google phishing attack; passwords have been changed and moved to a non-Google password manager, and other access methods invalidated. The request highlights how many persistence routes, such as app passwords, sessions and recovery options, need checking after a compromise.","why":"Google phishing attacks remain common and account recovery after compromise is genuinely difficult to do exhaustively.","tone":"neutral","entities":["Google","infosec community"],"summarized_at":"2026-10-02T18:23:19.742723Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1515},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Security experts seek full checklist for Google account recovery","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T18:22:08.837386Z","rank":8,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@deFractal/117372667071524411","author":"deFractal@infosec.exchange","title":null,"snippet":"Any # infosec or # Google folks know of an authoritative checklist of every way someone can persist in access a # GoogleAccount ? Someone fell for a Google phishing attack, and I’ve changed their passwords while shifting to a non-Google password manager, invalidated other…","posted_at":"2026-10-02T18:12:48Z","likes":1}],"elsewhere":[],"window":"7d"}}