logo

An important update (and apology) on our PoisonSeed blog

ID: 881a8605-c257-535e-9647-2c50dd9920ea

STIX ID: report--881a8605-c257-535e-9647-2c50dd9920ea

Feed Name: Expel Blog

Threat Score
15/100

Date Published: 2025-07-25

Date Updated: 2026-04-27

...
...

Expel issued a correction to a prior blog post that had claimed an attacker circumvented FIDO passkey cross-device authentication. Their re-analysis shows the attacker successfully phished a password and triggered a QR-initiated FIDO flow, but all MFA challenges failed and the attacker was not granted access; Expel apologizes, thanks community responders, and commits to stronger technical review and evidence transparency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.