authentication

Yep, Passkeys Still Have Problems

Passkeys still face significant issues in 2025, including vendor lock-in and usability challenges across different ecosystems. Users should engage with Credential Managers like Bitwarden, avoid relying solely on platform managers (Apple, Google, Microsoft), and consider Yubikeys for important accounts. The introduction of the FIDO Credential Exchange Specification offers some hope for transitioning between providers, but day-to-day usability remains problematic. Active user education on how Passkeys work and the benefits of robust Credential Managers is crucial to overcoming barriers to adoption. Miscommunication and forced options by service providers exacerbate user confusion and trust issues. Ultimately, a focus on user control and education is imperative to safely navigate the evolving landscape of digital security.

https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/

Microsoft 365 Users Targeted in Device Code Phishing Attacks

Microsoft 365 users are targeted by phishing attacks exploiting OAuth 2.0 device authorization. Attackers trick users into granting access tokens via emails with misleading content. Tools like Squarephish and Graphish facilitate these campaigns, allowing low-skilled actors to launch sophisticated attacks. Mitigation strategies include implementing Conditional Access policies to block or restrict device code flows.

https://www.helpnetsecurity.com/2025/12/18/microsoft-365-device-code-phishing/

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

TLDR: New phishing kits like BlackForce, GhostFrame, InboxPrime AI, and Spiderman use advanced tactics, including AI and MFA bypass, to steal credentials at scale. BlackForce targets brands, GhostFrame hides in iframes, InboxPrime automates email campaigns, and Spiderman replicates bank pages for European targets. These innovations make phishing attacks easier to execute and more difficult to detect.

https://thehackernews.com/2025/12/new-advanced-phishing-kits-use-ai-and.html

New ConsentFix Attack Hijacks Microsoft Accounts Via Azure CLI

ConsentFix attack hijacks Microsoft accounts via Azure CLI without passwords or MFA. It tricks users into submitting OAuth codes through a fake CAPTCHA on compromised sites, giving attackers full access to accounts using Azure authentication. Monitoring for unusual Azure CLI activity is recommended to detect this threat.

https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/

Scroll to Top