A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing

A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing-resistant, become an attack surface when the initial enrollment is intercepted. # iAuthFlowV2 # PhishingAsAService # PasskeySecurity # ThreatLandscape https:// cyberworldops.eu/en/passkeys-u sed-as-b

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing

mastodon:infosec-exchangeother36d ago kagi ↗

A new PhaaS toolkit named iAuthFlow V2 captures passkey registrations during phishing sessions and uses them as persistent backdoors that survive password resets. Passkeys, widely marketed as phishing-resistant, become an attack surface when the initial enrollment is intercepted. # iAuthFlowV2 # PhishingAsAService # PasskeySecurity # ThreatLandscape https:// cyberworldops.eu/en/passkeys-u sed-as-b