Tuesday 22 September 2026 06:01:37 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#passkey


Microsoft Sets a 2027 Clock on SMS Sign-In, and Entra Admins Have Work to Do

Published: 21 September 2026 16:13Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft is steering Entra ID tenants away from text-message sign-in and toward passkeys, turning an old convenience feature into a migration deadline.

When SSO Stops Being a Login Button and Becomes the Control Plane

Published: 21 September 2026 12:53Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A stage-by-stage look at identity shows why the real security question is not which SSO logo you buy, but how far the platform can stretch as the company and its app estate grow.

The Hidden Fight Behind MFA: Why Fit Beats Fame in Identity Security

Published: 21 September 2026 12:49Category: Cloud, SaaS & Identity SecurityAuthor: SHADOWFIREWALL

A 2026 MFA roundup puts the spotlight on a bigger truth: the safest login control is the one that matches the environment, especially when phishing-resistant methods and legacy app coverage diverge.

Passkeys Are Not One Product - They Are a Security Choice About Control

Published: 21 September 2026 12:48Category: Cloud, SaaS & Identity SecurityAuthor: SHADOWFIREWALL

A new wave of passwordless tools is less about replacing passwords and more about deciding whether trust lives on the device, in the identity provider, or inside a verified onboarding flow.

The Quiet Power Play Behind CIAM Shortlists

Published: 21 September 2026 12:46Category: Cloud, SaaS & Identity SecurityAuthor: AUDITWOLF

A 2026 roundup of eight customer identity platforms is really a map of modern login risk - who owns the identity boundary, how users recover access, and how much password debt an organization is still carrying.

The 48-Hour Trap: How Fake ChatGPT Billing Emails Try to Turn Trust Into Theft

Published: 18 September 2026 10:15Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A branded payment reminder can look routine, but in the wrong hands it becomes a fast path from inbox to credential-harvesting page.

Passkeys Become the Decoy in a Cloud Identity Trap

Published: 17 September 2026 16:20Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A familiar security term can now be used to lower suspicion, while the real target remains Microsoft 365 access, sessions, and tenant persistence.

Passkeys Move Into the State Gate: The UK’s Identity Reset Against Phishing

Published: 15 September 2026 10:52Category: Cloud, SaaS & Identity SecurityGeo: Europe / United KingdomAuthor: SHADOWFIREWALL

GOV.UK One Login is shifting millions of users toward passkeys, a change that reduces dependence on passwords but also makes device security and recovery flows far more important.

UK Identity Switch Narrows the Phishing Window, But Does Not Seal It Shut

Published: 15 September 2026 08:09Category: Cloud, SaaS & Identity SecurityGeo: Europe / United KingdomAuthor: AUDITWOLF

GOV.UK One Login is moving toward passkeys for more than 23 million users, a shift that weakens password and SMS-based attacks while leaving recovery and fallback design as the pressure points.

Passkeys Did Not Fail. The Human Workflow Did.

Published: 13 September 2026 14:03Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A pair of Microsoft-linked campaigns shows how modern fraud now targets email infrastructure and the recovery steps around cloud identity, not just passwords.

Android Turns Credential Migration Into a Controlled Handshake

Published: 11 September 2026 12:32Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Google has introduced a direct transfer path for passwords and passkeys between managers on Android, shifting a long-sensitive workflow away from export files and toward on-device, user-approved exchange.

How a Helpdesk Pretend Can Slip Past Passkey Security in Microsoft 365

Published: 10 September 2026 10:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

The dangerous part is not the passkey itself, but the human workflow around identity recovery, where urgency and trust can be turned into account takeover.

Fake Cell Towers, Real Theft: The SMS Blaster Playbook Targeting Argentine Phones

Published: 07 September 2026 16:31Category: Security Awareness & Social EngineeringGeo: South America / ArgentinaAuthor: PATCHKNIGHT

A portable rogue base station can push nearby phones onto weaker mobile conditions and deliver phishing texts that look like trusted carrier notices.

When Passwordless Is Not Endpointless: The Chrome Passkey Weak Spot

Published: 07 September 2026 16:18Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A compromised Windows PC can turn Google’s passkey workflow into a post-compromise target, showing that strong cryptography does not remove the need to trust the browser, sync layer, and recovery path.

Passkeys Are Not Broken - The Identity Layer Around Them Is

Published: 04 September 2026 18:25Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A set of 39 documented techniques shows how attackers can target prompts, enrollment, recovery, and synced credentials without defeating FIDO2 cryptography itself.

Inside Proton Pass’s Zero-Knowledge Push to Make Phishing Harder

Published: 04 September 2026 14:26Category: Cloud, SaaS & Identity SecurityGeo: Europe / SwitzerlandAuthor: AUDITWOLF

A password manager is never just a vault anymore: Proton Pass is bundling encrypted credentials, aliases, built-in 2FA, dark web monitoring, and passkeys into one identity-defense stack.

Hardware Keys Move Into the AI Cyber Perimeter

Published: 03 September 2026 04:02Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A partnership expansion into Australia and nine other countries lands alongside a stronger sign-in rule for OpenAI's Trusted Access for Cyber program, putting phishing-resistant authentication at the center of access control.

The Password Manager That Turned Identity Sprawl Into a Single Subscription

Published: 28 August 2026 08:32Category: Cloud, SaaS & Identity SecurityGeo: Europe / SwitzerlandAuthor: AUDITWOLF

A discounted bundle for encrypted passwords, passkeys, aliases, and leak alerts shows how consumer security is moving from isolated tools to layered identity control.

WhatsApp Hardens the Front Door: Passkeys, Stronger Recovery, and Call Clues

Published: 26 August 2026 12:40Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A new security update adds multiple passkeys, longer alphanumeric passwords, and caller context - a small set of changes that could matter a lot in a platform where trust is often tested before a message is even opened.

WhatsApp Tightens the Lock on Accounts and Scam Calls

Published: 26 August 2026 10:31Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

New security features point to a broader shift away from one-time codes and toward phishing-resistant authentication, with extra friction added before users trust an unknown caller.