A $10K phishing kit called iAuthFlow v2 uses browser-in-the-middle attacks to silently register attacker-controlled passkeys seconds after victims authenticate. The tool promises persistent access that survives password resets. Security teams must now hunt for rogue credentials during investigations.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Phishers Plant Attacker Passkeys That Survive Password Resets | 0 | 11.49 | 21-08-2026 |
| 2 | ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA | 0 | 8.51 | 20-02-2026 |
| 3 | Klue Breach Exposes Salesforce Data Across Cybersecurity Vendors as Icarus Claims Attack | 0 | 7 | 24-06-2026 |
| 4 | How legitimate cloud platforms enable phishers to bypass MFA | 0 | 10.36 | 04-08-2026 |
| 5 | heise-Angebot: iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr | 0 | 7 | 09-07-2026 |
| 6 | heise-Angebot: iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr | 0 | 14.31 | 24-07-2026 |
| 7 | Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers | 0 | 11.88 | 06-08-2026 |
| 8 | Malicious AI Coding Plugins Hit JetBrains Marketplace, Stealing API Keys From Developers | -2 | 8 | 17-06-2026 |
| 9 | Have I Been Pwned: Wurde Ihr Online-Konto gehackt? Finden Sie es heraus! | 0 | 7 | 17-06-2026 |