Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset

Jan 03, 2024NewsroomMalware / Data Theft Information stealing malware are actively taking advantage of an undocumented Google OAuth endpoint named MultiLogin to hijack user sessions and allow continuous access to Google services even after a password reset. According to CloudSEK, the critical exploit facilitates session persistence and cookie generation, enabling threat actors to maintain access…

BT misses Huawei equipment ban deadline

The deadline set by the UK government for telecoms operators to remove Huawei equipment from their core networks has elapsed, with BT falling a bit short. In November 2022, the government issued formal legal notices to telecoms operators – including BT – outlining their obligations to eliminate Huawei kit due to security concerns.  The initial…

BT misses Huawei equipment ban deadline

The deadline set by the UK government for telecoms operators to remove Huawei equipment from their core networks has elapsed, with BT falling a bit short. In November 2022, the government issued formal legal notices to telecoms operators – including BT – outlining their obligations to eliminate Huawei kit due to security concerns.  The initial…