GOV.UK One Login is opening passkeys to more than 23 million users, letting them sign in without a password.
Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.
A flaw in Brevo's single sign-on handling let an attacker blast phishing mail to 347,000 Trezor customers.
A new phishing kit enrolls attacker passkeys to keep access after password resets.
Malware can borrow Windows Hello for Business keys to open a 90-day persistence channel into Entra ID.
A widespread authentication failure at GitHub on May 26, 2026, halted software delivery by blocking access to Actions and Pages…
In 2025, the number of hardcoded secrets exposed in public repositories surged 47% year-over-year to 28.7 million, driven by the…