Tag: passkey
-
GNOME 51 adds passkey logins, offline maps and drawn PDF signatures
GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/gnome-51-new-features/
-
GNOME 51 adds passkey logins, offline maps and drawn PDF signatures
GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/gnome-51-new-features/
-
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-passkey-phishing-microsoft-365-cloud-data/
-
Your passkeys can now move between password managers on Android
Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/google-android-password-manager-transfer/
-
Passwd Review 2026: A Top Password Manager for Google Workspace
Passwd is a Google Workspace-focused password manager with strong usability, flexible pricing, passkey support, and private cloud deployment options. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/passwd-review/
-
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/
-
PassPasskey Bypasses MFA Without Breaking FIDO2
I have spent years arguing that passkeys are the right answer to phishing. The cryptography behind that argument is still sound. Research presented at Black Hat USA 2026 does not change it. What it changes is the assumption that deploying… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/pass-the-passkey-bypasses-mfa-without-breaking-fido2/
-
Protect your WhatsApp account with new passkey and 2FA upgrades
WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades/
-
Protect your WhatsApp account with new passkey and 2FA upgrades
WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades/
-
WhatsApp enhances account security with passkeys and stronger verification
Tags: passkeyFirst seen on scworld.com Jump to article: www.scworld.com/brief/whatsapp-enhances-account-security-with-passkeys-and-stronger-verification
-
WhatsApp Just Added 3 New Ways to Protect Your Account
Tags: passkeyWhatsApp is adding stronger two-step verification, multiple passkeys and more context for unknown callers as it expands protections against scams. The post WhatsApp Just Added 3 New Ways to Protect Your Account appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-whatsapp-security-updates-2fa-passkeys-caller-context/
-
WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information…
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys…
-
WhatsApp adds stronger two-step verification, multiple passkeys
Tags: passkeyWhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/
-
Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können
Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen. First seen on golem.de Jump to article: www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-passwort-reset-umgehen-koennen-2608-212226.html
-
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is…
-
The Enterprise Passkey Migration Decision Framework: When Device-Bound vs. Synced Passkeys Actually Matter
A decision framework for enterprise passkeys: when device-bound hardware keys beat synced passkeys, mapped to user risk, device context, compliance, and total cost. Includes the three failure patterns that surface only after rollout. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-enterprise-passkey-migration-decision-framework-when-device-bound-vs-synced-passkeys-actually-matter/
-
WebAuthn Level 3: What’s New in the Passkey Standard
WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/webauthn-level-3-whats-new-in-the-passkey-standard/
-
New Passkey attack reveals all the things we didn’t know about passkeys
Why passkey apps treat Windows differently than other operating systems. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/product-showcase-enpass-password-manager/
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
Why Passkeys Are Closing the Account Takeover Gap
HealthEquity’s Ajit Gaddam on Passwordless Security, Fraud Signals, Cyber Defense. Passwords remain a weak point in account security, especially when attackers can buy stolen credentials and exploit recovery workflows. Ajit Gaddam explains how passkeys, biometrics and device signals can strengthen identity assurance while reducing login friction. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/passkeys-are-closing-account-takeover-gap-a-32442

