Death to one-time text codes: Passkeys are the new hotness
Phishing-resistant multifactor authentication, such as passkeys and hardware-backed methods, is essential because SMS/email OTPs are vulnerable to phishing.
DraftKings Warns Users of Credential Stuffing Attacks
DraftKings detected a credential stuffing attack using externally harvested credentials that may have exposed user account data and is enforcing password resets and MFA.
Phishers have found a way to downgrade-not bypass-FIDO MFA
The phishing attack bypasses a multifactor authentication scheme based on FIDO, the standard considered immune to credential phishing attacks, leading to unauthorized access.