Cybersecurity Identity & Access Management MFA Phishing Social engineering

Oauth phishing bypasses passwords and MFA

The FBI warns of highly targeted OAuth consent phishing attacks aimed at prominent figures, their families, and acquaintances. Attackers impersonate government officials, media personnel, or known contacts, luring victims with fake file shares or meeting invitations. Granting permission to a malicious OAuth application gives attackers long-term access to emails, files, and other sensitive account data. […]

Multifactor Authentication Password Management Risk management Vulnerability

Passkeys are strong, but not untouchable

Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]

Password management
Password management

9 out of 10 passwords are too easy to retrieve

Everyone is annoyed when coming up with, remembering and entering hard-to-guess passwords as shown in this video. 77.6% of people find passwords difficult to remember, while 89.2% have an easy-to-guess or retrieve password, with 8% of all passwords already leaked. ID Control helps you manage your usernames, passwords and other secrets (e.g. credit card details) […]