By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: iAuthFlow V2 kit keeps access alive with attacker passkeys
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

iAuthFlow V2 kit keeps access alive with attacker passkeys

A new phishing kit enrolls attacker passkeys to keep access after password resets.

CSBadmin
Last updated: August 23, 2026 10:43 pm
CSBadmin
1 Min Read
Share
SHARE

A phishing toolkit named iAuthFlow V2, first spotted on a Russian-language cybercrime forum, can register an attacker-controlled passkey during an attack, giving criminals persistent account access even after the victim changes their password and active sessions are revoked.

Passkeys are meant to replace passwords with device-bound cryptographic credentials, but the kit shows the mechanism can be turned against its users. By enrolling the attacker’s passkey on the victim’s account, the tool leaves a backdoor that survives the standard response to a compromised login: password rotation and session termination. Researchers describe the development as evidence of the rapidly improving sophistication of phishing techniques.

The technique matters as passkey adoption spreads across enterprises. Security teams should treat passkey enrollment as a high-risk account action, watch for unexpected credential registration events, and monitor for authentication with newly added passkeys shortly after phishing activity. Defense-in-depth such as device attestation and step-up verification for passkey binding can blunt the attack.

The kit also underscores that credential-reset processes, long considered the safety net after a breach, no longer guarantee recovery when attackers control the recovery mechanism itself.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverAuthenticationcybercrimeMFApasskeysPhishing
SOURCES:SecurityWeek
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article LockBit threatens US Bank leak as lender points to vendor breach
Next Article SPECTRE backdoor shows how AI sharpens mass web server raids

Trending

Budget Android phones ship with malware already in the firmware
October 11, 2026
Wind and solar controls sit wide open on the web
October 10, 2026
Exposed GPU monitors hand attackers the keys to AI clusters
October 10, 2026
Unpatched backup server flaws become a path to crypto miners
October 11, 2026
Three teams bank $560,000 for cracking a Pixel 10
October 11, 2026

Related Stories

CSBadmin

Study Finds 282 iOS Apps Expose AI API Keys Through Network Traffic

CSBadmin

INTERPOL Ramz Initiative Targets Phishing and Scam Operations Across 13 Countries

CSBadmin

Malicious Payment SDK Packages Target Developers on NPM and PyPI

CSBadmin

MLflow and FUXA flaws draw scans aimed at cloud secrets

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.