By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: iAuthFlow V2 kit keeps access alive with attacker passkeys
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

iAuthFlow V2 kit keeps access alive with attacker passkeys

A new phishing kit enrolls attacker passkeys to keep access after password resets.

CSBadmin
Last updated: August 23, 2026 10:43 pm
CSBadmin
1 Min Read
Share
SHARE

A phishing toolkit named iAuthFlow V2, first spotted on a Russian-language cybercrime forum, can register an attacker-controlled passkey during an attack, giving criminals persistent account access even after the victim changes their password and active sessions are revoked.

Passkeys are meant to replace passwords with device-bound cryptographic credentials, but the kit shows the mechanism can be turned against its users. By enrolling the attacker’s passkey on the victim’s account, the tool leaves a backdoor that survives the standard response to a compromised login: password rotation and session termination. Researchers describe the development as evidence of the rapidly improving sophistication of phishing techniques.

The technique matters as passkey adoption spreads across enterprises. Security teams should treat passkey enrollment as a high-risk account action, watch for unexpected credential registration events, and monitor for authentication with newly added passkeys shortly after phishing activity. Defense-in-depth such as device attestation and step-up verification for passkey binding can blunt the attack.

The kit also underscores that credential-reset processes, long considered the safety net after a breach, no longer guarantee recovery when attackers control the recovery mechanism itself.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverAuthenticationcybercrimeMFApasskeysPhishing
SOURCES:SecurityWeek
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article LockBit threatens US Bank leak as lender points to vendor breach
Next Article SPECTRE backdoor shows how AI sharpens mass web server raids

Trending

Password reset bypass in Keycloak opens every account to takeover
August 24, 2026
Bogus rescue outfit double-dips on ransomware victims
August 24, 2026
Linux rig joins Apple Find My to pull live location feeds
August 24, 2026
764 offshoot leader gets record 77-year term for abuse spree
August 24, 2026
Slovak watchdog pulls speed cameras over hacking and data risks
August 24, 2026

Related Stories

CSBadmin

SonicWall Urges Immediate Patching of Firewall Vulnerabilities Affecting Gen 6, 7, and 8 Devices

CSBadmin

cPanelSniper Weaponizes cPanel Flaw, 44k Hosts at Risk

CSBadmin

CISA Mandates Three Day Patch Deadline for Critical Exploited Flaws

CSBadmin

FortiBleed Campaign Exploits 73,000 Fortinet Firewalls Across 194 Countries

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.