CISSP Cyber Training Podcast - CISSP Training Program

CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)

September 28, 2026·32 min
Episode Description from the Publisher

Send us Fan Mail A stolen password is annoying. A stolen session token can be invisible, valid, and instantly profitable. Today we dig into a real warning sign from Okta threat intelligence: infostealer malware lifted live session tokens from browsers, and thousands of Google sessions were still working weeks later. No MFA prompt. No brute force. Just a legitimate session replayed by the wrong person, with real dollar damage through unauthorized usage and credits. We use that story to sharpe...

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of CISSP Cyber Training Podcast - CISSP Training Program and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.