Home / Aug 23, 2026 / Story
0
#4 SecurityWeek general August 21, 2026 at 14:22 UTC

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

By Kevin Townsend

AI Summary

A new phishing toolkit called iAuthFlow V2 can register attacker-controlled passkeys during a phishing session, enabling persistent account access even after the victim resets their password and revokes active sessions. This directly undermines a core security assumption of passkey adoption and is critical intelligence for identity and authentication teams evaluating FIDO2 rollouts.

Relevance score: 78.0/100

# More from August 23