CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Sponsored: Passkeys won’t stop authorisation phishing

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6082

As cited

Copy frozen at (site build).

threat intel

Sponsored: Passkeys won’t stop authorisation phishing

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Sponsored: Passkeys won’t stop authorisation phishing

Attackers are shifting focus from authentication toward the authorization layer, exploiting device code phishing attacks that bypass passkeys and phishing-resistant multifactor authentication (MFA). Luke Jennings from Push Security discusses how these attacks persist despite stronger authentication controls and how defenders can validate their defenses against them.

Why it matters: Security teams relying on passkeys or phishing-resistant MFA need to assess authorization layer controls today, as attackers are actively exploiting this gap to gain access even when front-line authentication is hardened.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary