ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
A phishing kit sold on Russian-language cybercrime forums for around $10,000 enrolls attacker-controlled passkeys on compromised accounts. iAuthFlow v2 uses a browser-in-the-middle attack, demonstrated against Google, with packages for iCloud, LinkedIn, and Microsoft. The passkey remains valid after password changes, so defenders must audit newly enrolled credentials, OAuth grants, and mail rules.
Tracked by ByteBrief