news.mlab.sh
Back to the feed
threat-intel

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

High
Summary

A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a secondary browser environment to bypass standard security measures like password resets and session revocation, allowing attackers to retain persistent access to accounts. This represents a shift beyond traditional phishing and necessitates a revised approach to security.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.