logo

'PoisonSeed' Attacker Skates Around FIDO Keys

ID: 63e9b6d6-1c86-5b58-a36d-b5d1f45bed17

STIX ID: report--63e9b6d6-1c86-5b58-a36d-b5d1f45bed17

Feed Name: Dark Reading

Threat Score
25/100

Date Published: 2025-07-18

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Expel published research claiming a phishing campaign called "PoisonSeed" used a cross-device QR-code flow to bypass FIDO/passkey protections and access accounts, but subsequently retracted the findings after community and FIDO Alliance review, concluding the evidence did not support the attack and noting properly implemented FIDO cross-device authentication (with proximity checks) would mitigate the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.