passkeys3 articles
£8K Phishing Kit Promises to Plant Fake Passkeys and Haunt Compromised Accounts Long After You've Changed Your Password
A $10,000 phishing kit called iAuthFlow v2, advertised on Russian-language cybercrime forums, uses a browser-in-the-middle technique to hijack authentication sessions and secretly enroll attacker-controlled passkeys on compromised accounts — allowing persistent access even after victims change their passwords. The kit relays the victim's login interaction through an attacker-controlled browser, then exploits the authenticated session to register a rogue passkey, reportedly completing the process within seconds. Security researchers warn that incident response must go beyond password resets and session revocation, requiring a thorough audit of all post-compromise account changes, including newly enrolled passkeys, OAuth grants, and recovery methods.
Malware Can Hijack Passkey-Protected Accounts Through Google Password Manager Without Touching Your Screen
Researchers at Unit 42 have identified three attack techniques against Google Password Manager's passkey implementation in Chrome on Windows, which could allow malware already running on a victim's device to silently sign into passkey-protected accounts without any user interaction. The attacks exploit weaknesses in how Chrome stores device keys, handles device re-enrollment, and manages the 32-byte Security Domain Secret used to decrypt synced passkeys — rather than breaking the underlying cryptography. No CVEs have been assigned, the full remediation status is unclear, and it remains unknown whether actions like changing a Google Password Manager PIN would invalidate a secret an attacker has already obtained.
Banks Still Treating MFA as Optional. Your Money Pays the Price.
The author recounts how their 84-year-old mother lost $30,000 to thieves who exploited her reused passwords and lack of multi-factor authentication (MFA) to access her bank accounts, retirement savings, and Gmail. Despite many banks and Google offering MFA, they make it optional rather than mandatory, prioritising user convenience and avoiding friction over customer security. The article argues that financial institutions should require stronger, phishing-resistant MFA — such as passkeys — by default across all platforms, as optional security measures leave the majority of users dangerously exposed.