threat-intel
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
High
Summary
A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a secondary browser environment to bypass standard security measures like password resets and session revocation, allowing attackers to retain persistent access to accounts. This represents a shift beyond traditional phishing and necessitates a revised approach to security.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data