A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing
A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing-resistant, become an attack surface when the initial enrollment is intercepted. # iAuthFlowV2 # PhishingAsAService # PasskeySecurity # ThreatLandscape https:// cyberworldops.eu/en/passkeys-u sed-as-b