[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJvEzANtGsiyuxKGbsHyIdphOPNNuW7MuFvHYpKTo-II":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"6174595b-2bb8-4c26-90a7-1b1fe0a5cb79","phishing-toolkit-hijacks-passkeys-to-survive-password-resets","7c98fe8e-dce4-4b2c-8b21-1999c5cc38d4","Phishing Toolkit Hijacks Passkeys to Survive Password Resets","The iAuthFlow V2 toolkit exploits a critical gap in account recovery logic: once an attacker gains temporary access, they register an attacker-controlled passkey as a trusted credential, effectively creating a persistent backdoor that survives password resets and session revocations. This matters because many organizations and users treat password resets as a reliable incident response action, assuming it fully evicts an adversary — this toolkit invalidates that assumption. The attack also undermines the perceived security of passkeys, which are increasingly promoted as phishing-resistant, by weaponizing the credential registration process itself. Without visibility into registered authenticators and strict controls over who can add new credentials, defenders may have no idea the attacker is still present.","**Immediate actions:**\n- Audit all registered passkeys, authenticator apps, and trusted devices on high-value accounts and revoke any unrecognized credentials immediately.\n- When responding to a suspected account compromise, revoke ALL registered authentication methods — not just passwords and sessions — before re-onboarding the legitimate user.\n\n**Long-term improvements:**\n- Enforce admin approval workflows or step-up authentication (e.g., re-authentication + manager approval) before any new passkey or authenticator can be registered to an account.\n- Implement conditional access policies that restrict passkey registration to managed, compliant devices only, preventing registration from unknown or untrusted endpoints.\n- Educate users and help-desk staff that password resets alone do NOT fully secure a compromised account and that all authentication factors must be reviewed.\n\n**Detection measures:**\n- Alert on passkey or authenticator registration events, especially those occurring shortly after login from a new IP, unusual location, or outside business hours.\n- Integrate identity provider logs (Entra ID, Okta, Google Workspace) into your SIEM to correlate new credential registrations with phishing indicators or concurrent suspicious session activity.",[12,13,14,15,16,17,18,19,20,21,22],"NIST SP 800-63B Section 6.1 (Authenticator Lifecycle Management)","NIST AC-2 (Account Management)","NIST AC-17 (Remote Access)","NIST IR-4 (Incident Handling)","CIS Control 5 (Account Management)","CIS Control 6 (Access Control Management)","CIS Control 8 (Audit Log Management)","CIS Control 14 (Security Awareness and Skills Training)","MITRE ATT&CK T1556.006 (Modify Authentication Process: Multi-Factor Authentication)","MITRE ATT&CK T1098.005 (Account Manipulation: Device Registration)","GDPR Article 32 (Security of Processing — appropriate technical measures)","published","2026-08-21T16:21:44.805973+00:00","2026-08-21T16:21:44.519+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fnew-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets\u002F","new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets-a94f11","New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]