As passkeys gain mainstream adoption, credential stuffing loses effectiveness, forcing attackers to target weaker verification stages, which CISOs must now harden as a priority.
Attackers exploit the legitimate Microsoft authentication flow as an attack vector, bypassing traditional anti-phishing controls through social engineering lures.
Four ManageEngine products contain a critical vulnerability that allows unauthenticated attackers to perform account takeovers via manipulated SSO mechanisms.
Russian intelligence operatives are phishing not only Signal accounts but also their backup recovery keys — a single compromised key enables permanent access to all messages and account takeover.