Glossary
Passkey
A phishing-resistant authentication credential based on public-key cryptography, tied to a specific device and typically unlocked with a biometric or PIN, designed to replace passwords under the FIDO2/WebAuthn standard. Because there is no shared secret transmitted to the server, passkeys cannot be phished, reused, or leaked in a credential-database breach the way passwords can.
Recent coverage mentioning Passkey
39 Methods Compromise Passkey Authentication: Threat Analysis
Discover 39 published methods compromising passkey authentication, focusing on ecosystem flaws, UI manipulation, and enrollment abuse.
iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence
Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.
UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion
Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.
Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows
Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.
Advertisement