< ciso
brief />
Tag Banner

All news with #fido2 tag

29 articles

Research reveals practical weaknesses in passkey deployments

🔐 Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more →

AiTM Phishing Now Leading Entry Point for Law Firms

🛡️ eSentire's legal sector report shows Adversary-in-the-Middle (AiTM) phishing is now the primary initial access vector for law firms, responsible for 28.57% of incidents and surpassing conventional credential theft. The firm also noted a 20% YoY rise in attacks against legal organizations, with credential and identity-focused threats comprising 56.3% of all activity. The report highlights specific services and lures—such as the Tycoon2FA platform, ClickFix fake browser-error campaigns, and Microsoft Teams abuse—and urges adoption of phishing-resistant MFA like FIDO2 and conditional access controls.
read more →

Tycoon2FA takedown reshapes phishing landscape

🔎 Microsoft reports that disruption of the Tycoon2FA phishing-as-a-service platform drove a sharp decline in traditional phishing techniques, with platform-linked volume falling 92% from pre-takedown averages. The takedown reduced QR code and CAPTCHA-gated phishing and forced attackers to adapt, shifting to channels like Microsoft Teams and automated BEC campaigns. Microsoft recommends stronger email filtering and phishing-resistant authentication such as passkeys, FIDO keys, and multifactor protections to mitigate evolving threats.
read more →

Microsoft Entra ID makes passkeys default by 2026

🔐 Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, automatically enabling them for users currently relying on SMS and voice MFA. Those phone-based methods will be retired as native Entra capabilities on February 1, 2027, though organizations can use third-party telecom providers if needed. Users already on phishing-resistant methods like Windows Hello for Business, FIDO2 keys, or smart cards can continue using them without change.
read more →

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

WebAuthn Redirection Added to Browser RDP Clients

🔒 Prisma Browser added WebAuthn redirection to its in-browser RDP client, becoming the first non-Windows client to support Microsoft’s MS-RDPEWA protocol. The team found gaps in the spec, reverse-engineered undocumented Windows server behavior, and created a custom Chromium extension API to accept precomputed clientDataHash values. This approach reuses Chromium’s FIDO2 stack to support USB keys, Touch ID, Windows Hello and phone-as-authenticator transports.
read more →

Stopping AiTM Phishing: Defenses After Authentication

🛡️ AiTM phishing evades credential theft by intercepting session tokens after legitimate logins, rendering stronger passwords and many MFA approaches insufficient on their own. While FIDO2 and passkeys reduce exposure at the authentication step, session cookies remain bearer tokens that can be replayed. The article recommends three practical controls—bind sessions to managed devices, monitor post-authentication anomalies, and shorten high-value session lifetimes—combined with targeted user guidance to stop attackers from exploiting captured sessions.
read more →

UK NCSC Urges Businesses to Offer Passkeys by Default

🔐The UK National Cyber Security Centre now recommends offering passkeys as the default authentication option for consumer accounts, saying passwords are "no longer resilient enough" for modern threats. The agency highlights that FIDO2-based passkeys rely on device-bound cryptographic keys and local verification (biometrics or PINs), making them resistant to phishing and credential reuse. Where passkeys are not yet supported it advises using password managers and strong multi-factor verification, and warns organisations to secure account recovery and fallback processes.
read more →

Fixing Authentication: Resilient Interoperable Systems

🔐 Authentication is breaking at critical front lines because a fragmented mix of cards, readers, middleware and identity platforms rarely interoperate under real-world pressure. This brittle stack allows downgrades, fallback paths and patch regressions to undermine even passwordless and FIDO2 deployments, producing outages and safety risks in healthcare, government and aerospace. The article outlines three architectural shifts — modular secure elements, reader‑agnostic middleware and a unified credential ecosystem — and a five-point CISO action plan to remove weak fallbacks, require downgrade transparency, harden patching, embed interoperability in contracts and run constrained high‑value pilots.
read more →

6 Key Trends Reshaping the Identity and Access Market

🔐 The IAM market is shifting from traditional login and MFA toward treating identity as a security control plane, driven by demand for phishing-resistant authentication and stronger governance for non-human accounts. Buyers are prioritizing FIDO2/passkeys, biometrics, and controls for service accounts, API keys, and AI agents. Regulatory change, managed services, and vendor consolidation are reshaping architectures and procurement decisions.
read more →

Microsoft Entra Adds Phishing-Resistant Passkeys on Windows

🔐 Microsoft is introducing passkey support in Microsoft Entra for Windows, enabling phishing-resistant, passwordless sign-ins via Windows Hello. The opt-in feature enters public preview worldwide from mid‑March through late April 2026, with government clouds (GCC, GCC High, DoD) following mid‑April through mid‑May. Passkeys are device-bound, stored in the Windows Hello container, and never transmitted over the network, preventing credential theft and MFA bypass. IT administrators must enable the Passkeys (FIDO2) authentication method, create a passkey profile including the required Windows Hello AAGUIDs, and assign the profile to appropriate groups to enroll devices.
read more →

Bitwarden Enables Passkey Sign-in for Windows 11 Devices

🔐 Bitwarden now supports logging into Windows 11 using passkeys stored in the Bitwarden vault, enabling phishing‑resistant, passwordless sign-in across devices. The capability is available on all plans, including the free tier, and uses a QR scan and mobile confirmation to release a vault‑stored Entra ID passkey. Required: Entra ID–joined devices, FIDO2 sign‑in enabled, and a registered Entra ID passkey in the vault. Microsoft will roll out the Windows support this month, subject to Entra configuration.
read more →

CrowdStrike FalconID Adds Phishing-Resistant MFA Support

🔐 FalconID is now generally available, delivering phishing‑resistant, FIDO2-based authentication built into the Falcon sensor and delivered via the Falcon for Mobile app. It replaces passwords, push notifications and one‑time codes with biometric, device‑bound verification and cryptographic domain binding. Authentication decisions are driven by real‑time identity, endpoint and SaaS telemetry to minimize friction while blocking credential abuse. For legacy apps, FalconID offers secure indirect authentication, and when paired with SGNL it enables continuous, risk‑based authorization across environments.
read more →

Passwords to Passkeys: ISO 27001 Compliance Practical Guide

🔐 Password-based authentication is increasingly replaced by passkeys—FIDO2/WebAuthn-backed credentials that store private keys on devices and typically meet AAL2/AAL3 assurance per NIST SP 800-63B. This article explains how organizations can adopt passkeys while remaining compliant with ISO/IEC 27001, mapping changes to Annex A controls (Access Control, Authentication Information, Secure Authentication) and documenting risk treatment. It highlights benefits, common risks such as device loss and downgrade attacks, and practical migration steps for enterprise deployment.
read more →

Defending Against ShinyHunters Branded SaaS Extortion

🔐 Mandiant is tracking a notable expansion of ShinyHunters-branded extortion campaigns that use evolved vishing and victim-branded credential harvesting to compromise SSO credentials and enroll unauthorized devices into corporate MFA. These intrusions exploit social engineering — not product vulnerabilities — to pivot into cloud SaaS environments and perform bulk exports and administrative abuse. The post provides prioritized containment, hardening, logging, and detection guidance, and urges adoption of phishing-resistant MFA such as FIDO2 security keys and passkeys.
read more →

ShinyHunters Expansion Targets SaaS Identity and Data

🔎 Mandiant and Google GTIG observed an expansion of ShinyHunters-style campaigns using sophisticated vishing and victim-branded credential harvesting sites to steal SSO credentials and MFA codes. Compromised accounts were used to access a broadening set of cloud SaaS applications to locate confidential documents and PII for extortion. Activity attributed to clusters UNC6661, UNC6671, and UNC6240 includes harassment, DDoS, and Limewire-hosted proof samples. Organizations should adopt phishing-resistant MFA such as FIDO2 or passkeys and follow published hardening and detection guidance.
read more →

Microsoft: FIDO2 Security Keys May Require PIN on Windows

🔒 Microsoft warned that FIDO2 security keys may prompt users to create or enter a PIN after Windows updates beginning with the September 29, 2025 KB5065789 preview. This behavior affects devices running Windows 11 24H2 or 25H2 when a Relying Party or identity provider requests User Verification set to preferred. Microsoft says the change is intentional to align with the WebAuthn specification, which requires PIN setup when authenticators support user verification. Organizations that want to avoid PIN prompts can set user verification to discouraged in their WebAuthn settings.
read more →

Tycoon 2FA Kit Exposes Global Collapse of Legacy MFA

🔐 The Tycoon 2FA phishing kit is a turnkey, scalable Phishing-as-a-Service that automates real-time credential and MFA relay attacks against Microsoft 365 and Gmail. It provisions fake login pages and reverse proxies, intercepts usernames, passwords and session cookies, then proxies the MFA flow so victims unknowingly authenticate attackers. The kit includes obfuscation, compression, bot-filtering, CAPTCHA and debugger checks to evade detection and only reveals full behavior to human targets. Organizations are urged to adopt FIDO2-based, hardware-backed biometric and domain-bound authentication to prevent such relay attacks.
read more →

Tycoon 2FA Phishing Kit Undermines Legacy MFA Protections

🔐 Tycoon 2FA is a turnkey phishing kit that automates real-time MFA relays, enabling attackers to capture credentials, session cookies, and live authentication flows for Microsoft 365 and Gmail. It requires no coding skill, includes layered evasion (obfuscation, compression, bot filtering and debugger checks), and proxies MFA prompts so victims unknowingly authenticate attackers. The result undermines SMS, TOTP and push methods and can enable full session takeover. The article urges migration to phishing-resistant FIDO2 hardware and domain-bound biometric authenticators.
read more →

Windows 11 Adds Native Support for Third-Party Passkeys

🔐 Microsoft has added native Windows 11 support for third-party passkey managers, beginning with 1Password and Bitwarden. Introduced in the November 2025 security update, the platform-level passkey API lets Windows generate a cryptographic key pair while storing the private key in the chosen manager, and uses Windows Hello (PIN or biometric) to verify logins. Microsoft also integrated its Microsoft Password Manager from Edge into Windows so users can pick their preferred manager. The change aims to improve portability, phishing resistance, and ease of passwordless authentication across devices.
read more →