← Back to feed
general SecurityWeek

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

SecurityWeek

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions rev...

T1566
Read the full story SecurityWeek →

Related Coverage

general SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules Cyberscoop · Aug 24 general AWS patches flaw in 7 SDKs SC Media · Aug 24 general ShinyHunters claims social engineering attack against ReliaQuest SC Media · Aug 24