{"id":52298,"date":"2023-06-05T17:00:20","date_gmt":"2023-06-05T17:00:20","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34689\/Gmail-Spoofing-Vulnerability-Sparks-Google-Priority-1-Probe.html"},"modified":"2023-06-05T17:00:20","modified_gmt":"2023-06-05T17:00:20","slug":"gmail-spoofing-vulnerability-sparks-google-priority-1-probe","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/","title":{"rendered":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe"},"content":{"rendered":"<p>Google launched a \u201cPriority 1\u201d investigation into a Gmail security vulnerability after initially dismissing it as \u201cintended behavior\u201d that did not require a fix.<\/p>\n<p>The vulnerability relates to the <a href=\"https:\/\/bimigroup.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">Brand Indicators for Message Identification<\/a> (BIMI) email authentication method, a feature Google introduced to Gmail in 2021 but only recently rolled out to all 1.8 billion users of its email services.<\/p>\n<p>With BIMI, a blue tick verification symbol is displayed on emails when the brand logo displayed as the sender\u2019s avatar has been authenticated as matching the company claiming to be sending the email. BIMI is not exclusive to Google, rather it is part of ongoing efforts by a working group with a broad range of members who support the verification standard. The flaw brought to Google&#8217;s attention only impacts its own implementation of BIMI.<\/p>\n<p><strong>UPDATE<\/strong> (<em>6\/5 1:45pm ET<\/em>): In a statement to SC Media sent after this report initially published Google said:<\/p>\n<p>\u201cThis issue stems from a third-party security vulnerability allowing bad actors to appear more trustworthy than they are. To keep users safe, we are requiring senders to use the more robust DomainKeys Identified Mail (DKIM) authentication standard to qualify for Brand Indicators for Message Identification (blue checkmark) status.\u201d<\/p>\n<h2>Spoof-proof, at least in theory<\/h2>\n<p>When Google <a rel=\"noreferrer noopener\" href=\"https:\/\/workspaceupdates.googleblog.com\/2023\/05\/expanding-gmail-security-BIMI.html\" target=\"_blank\">announced the universal availability of BIMI<\/a> to all Google Workspace customers and personal Google account users on May 3, the company emphasized the security benefits of the feature.<\/p>\n<p>\u201cThis will help users identify messages from legitimate senders versus impersonators,\u201d Google said.<\/p>\n<p>\u201cStrong email authentication helps users and email security systems identify and stop spam, and also enables senders to leverage their brand trust. This increases confidence in email sources and gives readers an immersive experience, creating a better email ecosystem for everyone.\u201d<\/p>\n<p>Given Gmail Google Workspace\u2019s popularity as personal and business email platforms, users of the services are <a href=\"https:\/\/www.scmagazine.com\/news\/identity-and-access\/ghosttoken-vulnerability-permanently-expose-data-google-users\">natural targets for threat actors<\/a>.<\/p>\n<p>Less than a month after rolling out BIMI across the platforms, New Hampshire security architect Chris Plummer received a malicious spoofed email in his Google inbox that had been incorrectly check-marked to indicate it was sent by UPS.<\/p>\n<h2>Ups and downs of BIMI<\/h2>\n<p>Plummer <a href=\"https:\/\/twitter.com\/chrisplummer\/status\/1664076634876461056\" target=\"_blank\" rel=\"noreferrer noopener\">said on Twitter<\/a> he alerted Google to the vulnerability through its bug bounty program but the company rejected his report with the message \u201cwon\u2019t fix &#8211; intended behavior\u201d.<\/p>\n<div readability=\"8.4857142857143\">\n<blockquote class=\"twitter-tweet\" readability=\"10.371428571429\">\n<p lang=\"en\" dir=\"ltr\">The sender found a way to dupe <a href=\"https:\/\/twitter.com\/gmail?ref_src=twsrc%5Etfw\">@gmail<\/a>\u2019s authoritative stamp of approval, which end users are going to trust. This message went from a Facebook account, to a UK netblock, to O365, to me. Nothing about this is legit. Google just doesn\u2019t want to deal with this report honestly.<\/p>\n<p>\u2014 plum (@chrisplummer) <a href=\"https:\/\/twitter.com\/chrisplummer\/status\/1664076634876461056?ref_src=twsrc%5Etfw\">June 1, 2023<\/a><\/p><\/blockquote><\/div>\n<p>\u201cHow is a scammer impersonating @UPS in such a convincing way \u2018intended\u2019[?] he wrote. \u201cThe sender found a way to dupe @gmail\u2019s authoritative stamp of approval, which end users are going to trust. This message went from a Facebook account, to a UK netblock, to O365, to me. Nothing about this is legit.\u201d<\/p>\n<p>Plummer <a href=\"https:\/\/pastebin.com\/rZ8eSXU3\" target=\"_blank\" rel=\"noreferrer noopener\">posted the email headers<\/a> which indicated the spoofed message had failed the Sender Policy Framework (SPF) authentication process, another verification method.<\/p>\n<p>After his tweet went viral, Google\u2019s security team contacted Plummer to say they had had a change of heart over his bug bounty claim.<\/p>\n<p>\u201cAfter taking a closer look we realized that this indeed doesn&#8217;t seem like a generic SPF vulnerability. Thus we are reopening this and the appropriate team is taking a closer look at what is going on,\u201d their message said.<\/p>\n<h2>It&#8217;s a bug, not a feature<\/h2>\n<p>\u201cWe apologize again for the confusion and we understand our initial response might have been frustrating, thank you so much for pressing on for us to take a closer look at this!\u201d<\/p>\n<figure><img alt srcset=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=750&amp;q=75 1x, https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75 2x\" src=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\" width=\"697\" height=\"418\" decoding=\"async\" data-nimg=\"1\" class=\"MediaItem_img__WJ8V4\" loading=\"lazy\"><\/figure>\n<p>Plummer <a href=\"https:\/\/twitter.com\/chrisplummer\/status\/1664348988143722500?s=20\">posted a scr<\/a><a href=\"https:\/\/twitter.com\/chrisplummer\/status\/1664348988143722500?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">e<\/a><a href=\"https:\/\/twitter.com\/chrisplummer\/status\/1664348988143722500?s=20\">enshot<\/a> showing the investigation had been assigned a \u201cPriority P1\u201d status by Google.<\/p>\n<p>Commenting on Plummer\u2019s posts, one Twitter user said the problem appeared to be that UPS\u2019s main domain had an SPF record and the spoofer had circumvented that protection by using a related subdomain.<\/p>\n<p>\u201cThat subdomain don&#8217;t have a SPF record, and SPF is not meant to be inherited by subdomains. Perhaps it falls between the cracks because they&#8217;re using a subdomain.\u201d<\/p>\n<p>Another Twitter user said the email appeared to comply with BIMI because it passed the requirements of the <a href=\"https:\/\/www.scmagazine.com\/news\/application-security\/phishing-fears-cause-workers-to-reject-genuine-business-communications\" target=\"_blank\" rel=\"noreferrer noopener\">Domain Message Authentication Reporting and Conformance<\/a> (DMARC) authentication method.<\/p>\n<h2>Best laid plans of DMARK and SPF<\/h2>\n<p>\u201cIt passed DMARC because UPS use Microsoft for email (and it\u2019s in their SPF record), so you just need to send it from any Microsoft account.\u201d<\/p>\n<p>Another commenter said: \u201cGmail can&#8217;t fix the fact that [Microsoft] knowingly delivered [an email] that it KNEW failed SPF and DMARC.\u201d<\/p>\n<p>Plummer <a href=\"https:\/\/manchesterinklink.com\/nh-man-finds-glitch-in-google-security-matrix-potentially-saves-entire-gmailing-world-from-scammers\/\" target=\"_blank\" rel=\"noreferrer noopener\">told the Manchester Ink Link<\/a> he did not know \u201cwhy Google would get into the business of certifying email\u201d.<\/p>\n<p>\u201cIt was interesting that they were so bold in putting their own name on some of these communications [about the security benefits of the BIMI feature] when it relies on imperfect standards that are not within Google\u2019s control.\u201d<\/p>\n<p>He said he learned on June 2, via LinkedIn, that UPS had taken action as a result of him raising the vulnerability with Google.<\/p>\n<p>\u201cThat is unbelievable,\u201d he said. \u201cThat\u2019s an all-hands-on-deck kind of situation. I couldn\u2019t believe the research I did compelled a company like UPS to change its infrastructure and actually got Google interested in changing its product.\u201d<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34689\/Gmail-Spoofing-Vulnerability-Sparks-Google-Priority-1-Probe.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[10553],"class_list":["post-52298","post","type-post","status-publish","format-standard","hentry","category-packet-storm","tag-headlineprivacyemailflawgooglepassword"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-05T17:00:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe\",\"datePublished\":\"2023-06-05T17:00:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/\"},\"wordCount\":911,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\",\"keywords\":[\"headline,privacy,email,flaw,google,password\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/\",\"name\":\"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\",\"datePublished\":\"2023-06-05T17:00:20+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\",\"contentUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,privacy,email,flaw,google,password\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineprivacyemailflawgooglepassword\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/","og_locale":"en_US","og_type":"article","og_title":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-05T17:00:20+00:00","og_image":[{"url":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe","datePublished":"2023-06-05T17:00:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/"},"wordCount":911,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75","keywords":["headline,privacy,email,flaw,google,password"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/","url":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/","name":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75","datePublished":"2023-06-05T17:00:20+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#primaryimage","url":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75","contentUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F06%2FImage-from-Google.png&amp;w=1920&amp;q=75"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/gmail-spoofing-vulnerability-sparks-google-priority-1-probe\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,privacy,email,flaw,google,password","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineprivacyemailflawgooglepassword\/"},{"@type":"ListItem","position":3,"name":"Gmail Spoofing Vulnerability Sparks Google Priority 1 Probe"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52298"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52298\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}