#Passkeys
12 stories taggedPasskeys.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login
Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

Malware Can Silently Hijack Chrome Passkeys, Researchers Show
Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default for hundreds of millions of users.

Microsoft Is Killing SMS Login for Millions of Business Accounts. Here Is What Replaces It.
Starting September 2026, Microsoft will push passkeys as the default way to prove your identity in its business login system. By February 2027, the old text-message codes go dark entirely.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft login pages, and quietly locking themselves into corporate accounts before anyone notices. Okta has the details.

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.
Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

First-Day Passwords Are Still IAM's Soft Underbelly
Temporary onboarding credentials keep showing up in breach forensics. The problem isn't laziness — it's that most IT teams never actually defined what 'temporary' means.

The Week Identity Attacks Started Looking Like SaaS
Worm kits in public repos, a subscription RAT that clones live browser sessions, and AI agents that hand over credentials when asked nicely.

The 2026 Cybersecurity Stars Awards Land — 95 Categories, One Long Trophy Table
An industry awards program names winners across product, team, and company categories. The interesting question is what — if anything — the list tells us about where defenders are actually winning.

Infostealers Are Now the Front Door for Ransomware Gangs
Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.