• Nosotros
  • Publicidad
  • Trabaja con nosotros
  • Contactos
jueves, septiembre 3, 2026
  • Login
No Result
View All Result
NEWSLETTER
Despertar Matinal
  • Titulares del Día
    • All
    • En Portada
    Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

    Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

    Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

    Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

    Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

    Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

    Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

    Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

    “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

    “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

    Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

    Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

    Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

    Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

    Gobierno declara de alto interés nacional el combate al terrorismo ambiental

    Gobierno declara de alto interés nacional el combate al terrorismo ambiental

    Gobierno reporta crecimiento de la inversión extranjera y las exportaciones dominicanas

    Gobierno reporta crecimiento de la inversión extranjera y las exportaciones dominicanas

    Trending Tags

    • Mundo
      • All
      • América Latina
      • Conflictos Internacionales
      • Estados Unidos
      • Europa
      • Geopolítica
      • Haití
      • Medio Oriente
      El Banco Central adquirió USD 15 millones para sus reservas

      El Banco Central adquirió USD 15 millones para sus reservas

      Apareció muerto un exfuncionario kirchnerista que debía declarar por corrupción

      Apareció muerto un exfuncionario kirchnerista que debía declarar por corrupción

      Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

      Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

      Martín Demichelis recordó su paso por River y fue autocrítico: "Cometí errores"

      Martín Demichelis recordó su paso por River y fue autocrítico: «Cometí errores»

      Efectuaron operativos en Córdoba y Santa Fe por una causa de corrupción judicial

      Efectuaron operativos en Córdoba y Santa Fe por una causa de corrupción judicial

      Diego Milito hizo una profunda autocrítica por la situación de Racing: "Haberle renovado a Costas fue un error"

      Diego Milito hizo una profunda autocrítica por la situación de Racing: «Haberle renovado a Costas fue un error»

      Atento Colapinto: Andrea Kimi Antonelli arrancará último en el GP de Italia por una sanción

      Atento Colapinto: Andrea Kimi Antonelli arrancará último en el GP de Italia por una sanción

      Trump logró una histórica caída de casi 3 millones de inmigrantes ilegales en EEUU

      Trump logró una histórica caída de casi 3 millones de inmigrantes ilegales en EEUU

      Franco Colapinto celebró las mejoras en su A526 y anticipó las dificultades podrían afectar a Alpine en Monza

      Franco Colapinto celebró las mejoras en su A526 y anticipó las dificultades podrían afectar a Alpine en Monza

      Trending Tags

      • Nacionales
        • All
        • Bávaro Punta Cana
        • Educación
        • Gobierno
        • Infraestructura
        • Justicia
        • Obras Públicas
        • Opinión
        • Provincias
        • Seguridad Ciudadana
        • semana santa 2026
        • Sociedad
        • Transporte
        Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

        Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

        República Dominicana y Haití desarrollan agenda de trabajo sobre temas de interés bilateral

        República Dominicana y Haití desarrollan agenda de trabajo sobre temas de interés bilateral

        Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

        Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

        Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

        Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

        Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

        Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

        “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

        “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

        Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

        Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

        Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

        Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

        Gobierno declara de alto interés nacional el combate al terrorismo ambiental

        Gobierno declara de alto interés nacional el combate al terrorismo ambiental

        Trending Tags

        • Política
          • All
          • Congreso
          • Opinión Política
          • Partidos Políticos
          • Poder Municipal
          • Transparencia y Corrupción
          Fuerza del Pueblo denuncia aumentan las quejas por facturación elevada y persisten los apagones

          Fuerza del Pueblo denuncia aumentan las quejas por facturación elevada y persisten los apagones

          ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

          ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

          Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

          Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

          Antonio Marte juramenta nuevas estructuras fortalecen PPG

          Antonio Marte juramenta nuevas estructuras fortalecen PPG

          Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

          Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

          Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

          Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Trending Tags

          • Deportes
            • All
            • Atletas Dominicanos
            • Béisbol
            DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

            Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

            Buffalo recibe a Montreal para abrir la segunda ronda

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Trending Tags

            • Economía
              • All
              • Combustibles
              • Energía
              • Indicadores Económicos
              • Sector Energético
              • Turismo
              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aventúrate RD 2026

              Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

              El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

              Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

              Trending Tags

              • Ciencia
                • All
                • Energía
                • Innovación
                • Investigación Científica
                • Salud y Medicina
                • Tecnología Médica
                Australia is becoming a data centre capital - but at what cost?

                Australia is becoming a data centre capital – but at what cost?

                Trump $1 coin makes him first living president on US currency in a century

                Trump $1 coin makes him first living president on US currency in a century

                Palestinian teens killed during settler attack on West Bank village, officials say

                Palestinian teens killed during settler attack on West Bank village, officials say

                Gerónimo: “La gente está harta del Gobierno y sus fechorías”

                Gerónimo: “La gente está harta del Gobierno y sus fechorías”

                Huracán San Zenón del 3 de Septiembre de 1930: sube Trujillo

                Huracán San Zenón del 3 de Septiembre de 1930: sube Trujillo

                Gloria Steinem: Feminist activist and journalist dies, aged 92

                Gloria Steinem: Feminist activist and journalist dies, aged 92

                Vance's Antichrist comments are a 'common belief', his friend tells BBC

                Vance’s Antichrist comments are a ‘common belief’, his friend tells BBC

                Embattled Spanish PM Sánchez insists no prior warnings before Ceuta crisis

                Embattled Spanish PM Sánchez insists no prior warnings before Ceuta crisis

                South Africa's Sharpeville massacre survivors start legal fight for justice and compensation

                South Africa’s Sharpeville massacre survivors start legal fight for justice and compensation

                Trending Tags

                • Tecnología
                  • All
                  • Aplicaciones
                  • Inteligencia Artificial
                  'Welcome to the AGI era': OpenAI launches GPT-6 Astra

                  ‘Welcome to the AGI era’: OpenAI launches GPT-6 Astra

                  Los piratas informáticos vinculados a China abrieron puertas traseras a las computadoras portátiles de los ejecutivos a través de USB, explotando una solución que las empresas tenían pero que no estaban usando.

                  Los piratas informáticos vinculados a China abrieron puertas traseras a las computadoras portátiles de los ejecutivos a través de USB, explotando una solución que las empresas tenían pero que no estaban usando.

                  30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                  Científicos que estudian la leche de cucaracha y sonarse la nariz ganan premios Ig Nobel por ciencia peculiar

                  Meta dice que Muse Spark 1.3 tiene un rendimiento de vanguardia, pero sus mejores resultados provienen de un modelo que los desarrolladores aún no pueden utilizar ampliamente.

                  Meta dice que Muse Spark 1.3 tiene un rendimiento de vanguardia, pero sus mejores resultados provienen de un modelo que los desarrolladores aún no pueden utilizar ampliamente.

                  Un par de naves espaciales se acercan a Mercurio después de un viaje de casi una década

                  Un par de naves espaciales se acercan a Mercurio después de un viaje de casi una década

                  Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

                  Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

                  La brecha de visibilidad de la IA: por qué las grandes marcas se están alejando de las respuestas de la IA

                  La brecha de visibilidad de la IA: por qué las grandes marcas se están alejando de las respuestas de la IA

                  Nvidia gastará 13 mil millones de dólares en Hugging Face, dejándola como una plataforma de código abierto

                  Nvidia gastará 13 mil millones de dólares en Hugging Face, dejándola como una plataforma de código abierto

                  Muere a los 90 años el científico japonés Shirakawa, coganador del Premio Nobel de Química 2000

                  Muere a los 90 años el científico japonés Shirakawa, coganador del Premio Nobel de Química 2000

                  Trending Tags

                  • Entretenimiento
                    • All
                    • Cine y Series
                    • Cultura Digital
                    • Cultura Popular
                    • Gastronomía
                    • Música
                    Celine Dion está de regreso en París, pero su primera canción sigue siendo "un gran secreto"

                    Celine Dion está de regreso en París, pero su primera canción sigue siendo «un gran secreto»

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    La ‘Odisea’ de Emily Wilson se convirtió en un punto de inflamación cultural. Ahora ella está retraduciendo todo.

                    Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                    Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                    Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                    Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                    Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                    Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                    En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                    En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                    Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                    Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                    El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                    El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    Los británicos tienen la oportunidad de leer las memorias de Jason Arday en las librerías del Reino Unido

                    Trending Tags

                    • Titulares del Día
                      • All
                      • En Portada
                      Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

                      Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

                      Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

                      Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

                      Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

                      Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

                      Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

                      Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

                      “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

                      “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

                      Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

                      Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

                      Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

                      Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

                      Gobierno declara de alto interés nacional el combate al terrorismo ambiental

                      Gobierno declara de alto interés nacional el combate al terrorismo ambiental

                      Gobierno reporta crecimiento de la inversión extranjera y las exportaciones dominicanas

                      Gobierno reporta crecimiento de la inversión extranjera y las exportaciones dominicanas

                      Trending Tags

                      • Mundo
                        • All
                        • América Latina
                        • Conflictos Internacionales
                        • Estados Unidos
                        • Europa
                        • Geopolítica
                        • Haití
                        • Medio Oriente
                        El Banco Central adquirió USD 15 millones para sus reservas

                        El Banco Central adquirió USD 15 millones para sus reservas

                        Apareció muerto un exfuncionario kirchnerista que debía declarar por corrupción

                        Apareció muerto un exfuncionario kirchnerista que debía declarar por corrupción

                        Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

                        Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

                        Martín Demichelis recordó su paso por River y fue autocrítico: "Cometí errores"

                        Martín Demichelis recordó su paso por River y fue autocrítico: «Cometí errores»

                        Efectuaron operativos en Córdoba y Santa Fe por una causa de corrupción judicial

                        Efectuaron operativos en Córdoba y Santa Fe por una causa de corrupción judicial

                        Diego Milito hizo una profunda autocrítica por la situación de Racing: "Haberle renovado a Costas fue un error"

                        Diego Milito hizo una profunda autocrítica por la situación de Racing: «Haberle renovado a Costas fue un error»

                        Atento Colapinto: Andrea Kimi Antonelli arrancará último en el GP de Italia por una sanción

                        Atento Colapinto: Andrea Kimi Antonelli arrancará último en el GP de Italia por una sanción

                        Trump logró una histórica caída de casi 3 millones de inmigrantes ilegales en EEUU

                        Trump logró una histórica caída de casi 3 millones de inmigrantes ilegales en EEUU

                        Franco Colapinto celebró las mejoras en su A526 y anticipó las dificultades podrían afectar a Alpine en Monza

                        Franco Colapinto celebró las mejoras en su A526 y anticipó las dificultades podrían afectar a Alpine en Monza

                        Trending Tags

                        • Nacionales
                          • All
                          • Bávaro Punta Cana
                          • Educación
                          • Gobierno
                          • Infraestructura
                          • Justicia
                          • Obras Públicas
                          • Opinión
                          • Provincias
                          • Seguridad Ciudadana
                          • semana santa 2026
                          • Sociedad
                          • Transporte
                          Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

                          Presidente Abinader destaca reducción de la pobreza y avances sociales y económicos de República Dominicana

                          República Dominicana y Haití desarrollan agenda de trabajo sobre temas de interés bilateral

                          República Dominicana y Haití desarrollan agenda de trabajo sobre temas de interés bilateral

                          Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

                          Aseguran auditoría de la Cámara de Cuentas no encontró irregularidades en la gestión de Roberto Fulcar al frente del MINERD

                          Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

                          Recesan juicio de fondo contra Hugo Beras, Jochi Gómez y compartes

                          Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

                          Robinson Díaz: “Collado con 55% duplica a la oposición; será presidente; tiene 80% del PRM; Abinader será arbitro”

                          “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

                          “La gente está harta del Gobierno del PRM y sus fechorías”, asegura Joaquín Gerónimo

                          Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

                          Rector del ITLA anuncia que la meta para 2027 será duplicar su matrícula

                          Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

                          Presidente Abinader advierte sanciones de hasta 30 años de prisión a quienes afecten parques nacionales

                          Gobierno declara de alto interés nacional el combate al terrorismo ambiental

                          Gobierno declara de alto interés nacional el combate al terrorismo ambiental

                          Trending Tags

                          • Política
                            • All
                            • Congreso
                            • Opinión Política
                            • Partidos Políticos
                            • Poder Municipal
                            • Transparencia y Corrupción
                            Fuerza del Pueblo denuncia aumentan las quejas por facturación elevada y persisten los apagones

                            Fuerza del Pueblo denuncia aumentan las quejas por facturación elevada y persisten los apagones

                            ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

                            ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

                            Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                            Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                            Antonio Marte juramenta nuevas estructuras fortalecen PPG

                            Antonio Marte juramenta nuevas estructuras fortalecen PPG

                            Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

                            Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

                            Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

                            Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Trending Tags

                            • Deportes
                              • All
                              • Atletas Dominicanos
                              • Béisbol
                              DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

                              Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                              Buffalo recibe a Montreal para abrir la segunda ronda

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Trending Tags

                              • Economía
                                • All
                                • Combustibles
                                • Energía
                                • Indicadores Económicos
                                • Sector Energético
                                • Turismo
                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aventúrate RD 2026

                                Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

                                El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

                                Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

                                Trending Tags

                                • Ciencia
                                  • All
                                  • Energía
                                  • Innovación
                                  • Investigación Científica
                                  • Salud y Medicina
                                  • Tecnología Médica
                                  Australia is becoming a data centre capital - but at what cost?

                                  Australia is becoming a data centre capital – but at what cost?

                                  Trump $1 coin makes him first living president on US currency in a century

                                  Trump $1 coin makes him first living president on US currency in a century

                                  Palestinian teens killed during settler attack on West Bank village, officials say

                                  Palestinian teens killed during settler attack on West Bank village, officials say

                                  Gerónimo: “La gente está harta del Gobierno y sus fechorías”

                                  Gerónimo: “La gente está harta del Gobierno y sus fechorías”

                                  Huracán San Zenón del 3 de Septiembre de 1930: sube Trujillo

                                  Huracán San Zenón del 3 de Septiembre de 1930: sube Trujillo

                                  Gloria Steinem: Feminist activist and journalist dies, aged 92

                                  Gloria Steinem: Feminist activist and journalist dies, aged 92

                                  Vance's Antichrist comments are a 'common belief', his friend tells BBC

                                  Vance’s Antichrist comments are a ‘common belief’, his friend tells BBC

                                  Embattled Spanish PM Sánchez insists no prior warnings before Ceuta crisis

                                  Embattled Spanish PM Sánchez insists no prior warnings before Ceuta crisis

                                  South Africa's Sharpeville massacre survivors start legal fight for justice and compensation

                                  South Africa’s Sharpeville massacre survivors start legal fight for justice and compensation

                                  Trending Tags

                                  • Tecnología
                                    • All
                                    • Aplicaciones
                                    • Inteligencia Artificial
                                    'Welcome to the AGI era': OpenAI launches GPT-6 Astra

                                    ‘Welcome to the AGI era’: OpenAI launches GPT-6 Astra

                                    Los piratas informáticos vinculados a China abrieron puertas traseras a las computadoras portátiles de los ejecutivos a través de USB, explotando una solución que las empresas tenían pero que no estaban usando.

                                    Los piratas informáticos vinculados a China abrieron puertas traseras a las computadoras portátiles de los ejecutivos a través de USB, explotando una solución que las empresas tenían pero que no estaban usando.

                                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                    Científicos que estudian la leche de cucaracha y sonarse la nariz ganan premios Ig Nobel por ciencia peculiar

                                    Meta dice que Muse Spark 1.3 tiene un rendimiento de vanguardia, pero sus mejores resultados provienen de un modelo que los desarrolladores aún no pueden utilizar ampliamente.

                                    Meta dice que Muse Spark 1.3 tiene un rendimiento de vanguardia, pero sus mejores resultados provienen de un modelo que los desarrolladores aún no pueden utilizar ampliamente.

                                    Un par de naves espaciales se acercan a Mercurio después de un viaje de casi una década

                                    Un par de naves espaciales se acercan a Mercurio después de un viaje de casi una década

                                    Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

                                    Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

                                    La brecha de visibilidad de la IA: por qué las grandes marcas se están alejando de las respuestas de la IA

                                    La brecha de visibilidad de la IA: por qué las grandes marcas se están alejando de las respuestas de la IA

                                    Nvidia gastará 13 mil millones de dólares en Hugging Face, dejándola como una plataforma de código abierto

                                    Nvidia gastará 13 mil millones de dólares en Hugging Face, dejándola como una plataforma de código abierto

                                    Muere a los 90 años el científico japonés Shirakawa, coganador del Premio Nobel de Química 2000

                                    Muere a los 90 años el científico japonés Shirakawa, coganador del Premio Nobel de Química 2000

                                    Trending Tags

                                    • Entretenimiento
                                      • All
                                      • Cine y Series
                                      • Cultura Digital
                                      • Cultura Popular
                                      • Gastronomía
                                      • Música
                                      Celine Dion está de regreso en París, pero su primera canción sigue siendo "un gran secreto"

                                      Celine Dion está de regreso en París, pero su primera canción sigue siendo «un gran secreto»

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      La ‘Odisea’ de Emily Wilson se convirtió en un punto de inflamación cultural. Ahora ella está retraduciendo todo.

                                      Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                                      Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                                      Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                                      Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                                      Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                                      Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                                      En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                                      En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                                      Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                                      Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                                      El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                                      El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      Los británicos tienen la oportunidad de leer las memorias de Jason Arday en las librerías del Reino Unido

                                      Trending Tags

                                      No Result
                                      View All Result
                                      Despertar Matinal
                                      No Result
                                      View All Result

                                      Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

                                      by — Redacción Despertar Matinal
                                      2 de septiembre de 2026
                                      in Tecnología
                                      0
                                      Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
                                      0
                                      SHARES
                                      2
                                      VIEWS
                                      Share on FacebookShare on Twitter

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      ¡No te pierdas las noticias destacadas!

                                      Suscríbete y recibe las historias más importantes del día.

                                      Al suscribirte aceptas nuestros términos y condiciones y política de privacidad.

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.

                                      The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.

                                      The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.

                                      Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.

                                      It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. «Your Claude session was likely one of the many things it collected,» the email said.

                                      A session cookie is the proof that a login already happened

                                      The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.

                                      How a stolen session cookie bypasses 2FA and reaches a personal Claude account’s connector grants into corporate Google Workspace. Credit: VentureBeat made with Gemini

                                      Signing the accounts out worked because a replayed cookie dies with the session it copies.

                                      Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.

                                      Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.

                                      One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.

                                      Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.

                                      Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.

                                      Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.

                                      The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for «Claude Desktop app» straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.

                                      Refunds cover the usage. Nothing covers the connectors

                                      A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.

                                      If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.

                                      Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.

                                      Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim «in order to conduct operations and generate massive bills as a byproduct of that,» he said. «So think of this as LLM coin mining.»

                                      One architect refused to build the same exposure into his product

                                      Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.

                                      «We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.»

                                      Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.

                                      An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.

                                      Asked what was acceptable in 2024 and a liability now, he named one thing. «Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.»

                                      Okta gave agents governed identities the same week Claude users lost their cookies

                                      Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.

                                      Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.

                                      VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.

                                      That 3% has a reason, Kayne McGladrey, author of the forthcoming «Cyber Risk is a Myth» and a senior IEEE member, told VentureBeat during a July interview. «It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,» he said.

                                      The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.

                                      «If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.»

                                      Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.

                                      Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.

                                      The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. «I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,» he argued.

                                      The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.

                                      Each of those owners is paid to close a different gap. «Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,» he argued. «People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.»

                                      What security leaders need to do next

                                      Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.

                                      Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.

                                      Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.

                                      Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.

                                      Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.

                                      Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.

                                      Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.

                                      Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.

                                      ● Canal oficial · Gratis
                                      ¡Recibe las noticias antes que nadie!
                                      Únete a nuestro canal de WhatsApp y mantente informado al instante, sin spam.
                                      Unirme ahora →
                                      ● Noticias al instante ● Cobertura nacional ● Periodismo real Despertar Matinal
                                      — Redacción Despertar Matinal

                                      — Redacción Despertar Matinal

                                      Programa radial que te conecta con la información desde temprano en la mañana.

                                      Next Post
                                      Adriana Baravalle se reunió con el CEO de NVIDIA y un funcionario de Trump en el marco del G20

                                      Adriana Baravalle se reunió con el CEO de NVIDIA y un funcionario de Trump en el marco del G20

                                      Deja una respuesta Cancelar la respuesta

                                      Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

                                      Canal de WhatsApp

                                      WhatsApp logo WhatsApp

                                      Canal · Despertar Matinal

                                      Únete a nuestro
                                      Canal

                                      Seguir ahora

                                      El clima

                                      Canal de YouTube

                                      YouTube

                                      Canal · Despertar Matinal

                                      Mira nuestro
                                      Canal

                                      Ver ahora

                                      Escúchanos en Spotify

                                      Spotify

                                      Podcast · Despertar Matinal

                                      Escucha nuestro
                                      Podcast

                                      Escuchar ahora

                                      Noticias Populares

                                      • Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

                                        Inesperado: un campeón del mundo con España se retiró de su selección a los 31 años

                                        0 shares
                                        Share 0 Tweet 0
                                      • Apareció muerto un exfuncionario kirchnerista que debía declarar por corrupción

                                        0 shares
                                        Share 0 Tweet 0
                                      • Diego Milito hizo una profunda autocrítica por la situación de Racing: «Haberle renovado a Costas fue un error»

                                        0 shares
                                        Share 0 Tweet 0
                                      • ‘Welcome to the AGI era’: OpenAI launches GPT-6 Astra

                                        0 shares
                                        Share 0 Tweet 0
                                      • Toto Caputo destruyó a la UIA: “Defiendo los intereses de los argentinos, no los de algunos”

                                        0 shares
                                        Share 0 Tweet 0

                                      Medio digital independiente con análisis, opinión y periodismo responsable desde República Dominicana.

                                      Secciones populares

                                      • Política
                                      • Economía & Negocios
                                      • Justicia
                                      • Turismo
                                      • Tecnología
                                      • Entretenimiento
                                      • Mundo
                                      • Cine y Series
                                      • Música
                                      • Moda

                                      Contenido

                                      • Titulares del Día
                                      • Mundo
                                      • Nacionales
                                      • Política
                                      • Deportes
                                      • Economía & Negocios
                                      • Ciencia
                                      • Entretenimiento
                                      • Podcast
                                      • Opinión
                                      • Despertar Matinal TV
                                      • Editoriales

                                      Corporativo

                                      • Sobre nosotros
                                      • Publicidad
                                      • Sala de prensa
                                      • Contacto
                                      • Política de Privacidad
                                      • Eliminación de Datos

                                      Boletines

                                      Suscríbete a nuestro boletín
                                      Recibe las noticias más importantes cada mañana.

                                      • Nosotros
                                      • Publicidad
                                      • Trabaja con nosotros
                                      • Contactos

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      No Result
                                      View All Result
                                      • Home

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      Welcome Back!

                                      Login to your account below

                                      Forgotten Password?

                                      Retrieve your password

                                      Please enter your username or email address to reset your password.

                                      Log In

                                      Desarrollado por
                                      ►
                                      Las cookies necesarias habilitan funciones esenciales del sitio como inicios de sesión seguros y ajustes de preferencias de consentimiento. No almacenan datos personales.
                                      Ninguno
                                      ►
                                      Las cookies funcionales soportan funciones como compartir contenido en redes sociales, recopilar comentarios y habilitar herramientas de terceros.
                                      Ninguno
                                      ►
                                      Las cookies analíticas rastrean las interacciones de los visitantes, proporcionando información sobre métricas como el número de visitantes, la tasa de rebote y las fuentes de tráfico.
                                      Ninguno
                                      ►
                                      Las cookies de publicidad ofrecen anuncios personalizados basados en tus visitas anteriores y analizan la efectividad de las campañas publicitarias.
                                      Ninguno
                                      ►
                                      Las cookies no clasificadas son aquellas que estamos en proceso de clasificar, junto con los proveedores de cookies individuales.
                                      Ninguno
                                      Desarrollado por