#4
SecurityWeek
general
August 21, 2026 at 14:22 UTC
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
By Kevin Townsend
AI Summary
A new phishing toolkit called iAuthFlow V2 can register attacker-controlled passkeys during a phishing session, enabling persistent account access even after the victim resets their password and revokes active sessions. This directly undermines a core security assumption of passkey adoption and is critical intelligence for identity and authentication teams evaluating FIDO2 rollouts.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →