FIDO2 stories
With phishing and stolen credentials driving most breaches, organisations are being urged to replace passwords with passkeys for safer logins.
More than six million Britons may be exposing accounts to hackers by using one password across email, banking, shopping and social media.
Google says the campaign is shifting towards financial and legal firms, with rebranded extortion sites still stealing cloud logins and tokens.
Phishing-resistant logins could curb account takeovers that let criminals tamper with tax data, refunds and audit trails across firms.
Victims can be tricked more easily as Logokit now tailors fake login pages in real time, sending stolen credentials to Telegram bots.
The update could let companies use a single security key to approve payments, documents and AI actions without custom cryptography.
Access to ChatGPT and GPT-5.6 is being tightened for some accounts as OpenAI moves to hardware-backed passkeys amid rising phishing risk.
Users relying on SMS or voice for sign-ins will be nudged to passkeys as Microsoft phases out weaker multifactor methods in Entra ID.
Users who miss the deadline will lose access to OpenAI's most advanced cyber models, as the firm tightens defences against phishing.
Android users and IT teams can now deploy YubiKeys as hardware-backed passkeys, following Google Play Services support for NFC security keys.
Users can now store passkeys and share vault items securely as ExpressKeys expands beyond basic password management in a major update.
The upgrade gives government and regulated buyers a single device for legacy smart cards and passkeys, as agencies shift to stricter security rules.
A zero-day in a widely used Japanese learning platform let hackers plant malware, while Chinese phishing services are now bypassing one-time codes.
AI has made stolen credentials and careless copy-paste habits a bigger risk than password strength, with scams and breaches accelerating.
Session cookie theft lets attackers slip past multifactor checks, putting enterprise email accounts at risk even after login.
ChatGPT users can now buy a discounted two-pack of hardware keys designed to block phishing and protect sensitive accounts.
Fraudsters are exploiting tax season by stealing credentials and filing bogus returns, putting Australian refunds and ATO accounts at risk.
Stolen credentials are fuelling fraud as attackers bypass ATO controls, exposing taxpayers and forcing tax agents to harden logins.
Rising cyber threats and hybrid work are pushing Australian employers to replace scattered badges, passwords and tokens with one credential.
Australian firms are being urged to adopt passwordless logins as AI tools and data leakage make stolen credentials easier to exploit.