← Back to the feed

~/article/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-res-bchq6v
lowSource: SecurityWeek

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.

Read at the source

Summary written for cymesh.dev. The full article lives at SecurityWeek.

Topics

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks