Vulnerability Management

Patch prioritization, CISA KEV catalog, exploit availability, and vulnerability lifecycle.

The $10,000 Kit That Plants Its Own Passkey

A criminal is currently selling a phishing kit for $10,000 that claims it can register its own passkey on a victim's account during login, one that survives a password reset. Nobody has tested whether the kit actually works. But a separate research team already proved a real Google account can be tricked into accepting exactly that kind of rogue passkey, using a completely different method.

Patching the hole doesn't evict whoever already crawled through it

Most companies with remote or hybrid employees use a device sitting at the edge of their network, a box that lets people log in securely from home the same way they would sit at a desk in the office. SonicWall makes one of the most common versions of this box. Security researchers at Volexity, who investigate breaches for a living, discovered that attackers had been breaking into these devices and taking full control of them, not just peeking in, since June 22. SonicWall did not have a fix ready until July 14, more than three weeks later.