Cybersecurity News

Filters
Tag
Reset

Filtered by tag: account security × Clear

This new malware can use Google passkeys even after a victim resets their password

Researchers have discovered a malware toolkit called Atlantis AIO that can bypass multi-factor authentication and maintain access to Gmail, Microsoft, Apple, and LinkedIn accounts even after victims reset their passwords. The malware exploits session cookies and OAuth tokens, meaning credential changes don't revoke access. It automates credential-stuffing attacks across over 140 platforms.