New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Summary
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek .
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.