iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
ID: 68fcbe0d-69e9-51e4-aa34-e3afb3f70c4c
STIX ID: report--68fcbe0d-69e9-51e4-aa34-e3afb3f70c4c
Feed Name: Security Affairs
Threat Score
**iAuthFlow v2 phishing toolkit enables persistent account takeover by enrolling attacker-controlled passkeys after a successful phishing-based Google login, allowing adversaries to regain access even after victims change their passwords; the report details the browser-in-the-middle relay technique, automated passkey enrollment, demo timelines, potential use against other providers, and recommended containment and mitigation steps.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
