Cybercriminals are using a new type of malware named ‘MultiLogin’, which abuses Google’s OAuth endpoint to sign back into user accounts by reviving expired cookies, according to a report by BleepingComputer. The malware reportedly pilfered tokens and account data from Google accounts, including saved passwords to ensure ongoing access to these accounts. Google has yet to acknowledge or suggest mitigation measures for this threat.

Active Exploitation Alert: WP2Shell Critical WordPress Core Vulnerabilities (CVE-2026-63030 & CVE-2026-60137) Enable Unauthenticated RCE in the Wild – Rescana
Active Exploitation Alert: WP2Shell Critical WordPress Core Vulnerabilities (CVE-2026-63030 & CVE-2026-60137) Enable Unauthenticated RCE in the Wild Rescana


