PoisonSeed Attack Downgrades FIDO2 MFA Using Novel Phishing Tactics

TL;DR
PoisonSeed threat actors are bypassing FIDO2 security keys by exploiting the cross-device sign-in feature in WebAuthn, tricking users into approving login requests from fake portals. This attack does not exploit a flaw in FIDO2 but abuses a legitimate feature, prompting organizations to implement additional security measures such as geographic restrictions and Bluetooth authentication. The attack highlights evolving methods to circumvent phishing-resistant authentication systems.
- Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack BleepingComputer
- 'PoisonSeed' Attacker Skates Around FIDO Keys Dark Reading | Security
- Phishing attack abuses QR codes to bypass FIDO keys SC Media
- Phishers have found a way to downgrade—not bypass—FIDO MFA Ars Technica
- Hackers Exploit FIDO MFA With Novel Phishing Technique BankInfoSecurity
Want the full story? Read the original reporting
Read on BleepingComputer