threat-intel WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android WhatsApp is bolstering its security by introducing passkeys and enhanced two-step verification to combat phishing attacks and improve account protection for users on both iOS and Android. This move aims to make it significantly harder for malicious actors to gain unauthorized access to user accounts. The Hacker News · 5d ago Medium passkeysphishingsecurity
threat-intel WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update WhatsApp has significantly boosted its account security by introducing multi-passkey support, upgrading two-step verification to stronger passwords, and providing caller information to combat scams. These changes aim to… SecurityWeek · 5d ago Medium passkeystwo-factorsecurity
vulnerability Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Researchers have discovered a vulnerability in Apple's iCloud Private Relay tool that allows users' real IP addresses to be exposed, even when the tool is active. The issue stems from three WebKit features – DNS prefetch… The Hacker News · Aug 6, 2026 High webkitprivacyip leak
threat-intel Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Unit 42 researchers discovered three attack paths within Google Password Manager in Chrome that could allow malware to hijack passkey-protected accounts without requiring a fingerprint, PIN, or any user interaction. Thes… The Hacker News · Aug 3, 2026 High passkeyssecurityauthentication
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover
threat-intel Robinhood Cuts Access Approval Time to Support High-Velocity Development This Dark Reading article reports on Robinhood’s efforts to streamline its system access approval process to support faster development cycles and incident response. The company’s previous reliance on company-managed dev… Dark Reading · Jun 25, 2026 Medium application securityremote accessincident response