SecurityWeek

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

PhishingHighphishing

Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.

AI summary · generated with Claude

https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/