Return to Threats

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

securityweek.com 2026-08-21 malicious AI use Medium

What Happened

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek .

Why It Matters

Researchers report that the iAuthFlow V2 phishing toolkit can register attacker-controlled passkeys during phishing flows, allowing persistent access to victim accounts even after passwords are changed and active sessions are revoked. This demonstrates an evolution in credential phishing that targets modern authentication mechanisms rather than only passwords. From a RealGround perspective, this highlights that organizations adopting passkeys and modern auth flows must update threat models, security controls, and incident response playbooks to account for adversaries abusing legitimate WebAuthn/passkey registration flows. Practical security implications include hardening MFA enrollment and recovery processes, monitoring for anomalous passkey registrations, and red-teaming auth journeys to ensure that security policies and AI-driven fraud/risk engines correctly detect and respond to these new persistence techniques.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/

Talk to AI CISO