New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
The post https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/">New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on https://www.securityweek.com">SecurityWeek.