{"id":703,"date":"2025-07-21T09:35:59","date_gmt":"2025-07-21T07:35:59","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=703"},"modified":"2025-07-21T09:35:59","modified_gmt":"2025-07-21T07:35:59","slug":"poisonseed-hackers-bypass-fido-keys-using-qr-phishing-and-cross-device-sign-in-abuse","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/07\/21\/poisonseed-hackers-bypass-fido-keys-using-qr-phishing-and-cross-device-sign-in-abuse\/","title":{"rendered":"PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity researchers have disclosed a novel attack technique that allows threat actors to bypass Fast IDentity Online (<a href=\"https:\/\/fidoalliance.org\/\" rel=\"noreferrer noopener\" target=\"_blank\">FIDO<\/a>) key protections by deceiving users into approving authentication requests from spoofed company login portals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FIDO keys are hardware- or software-based authenticators designed to eliminate phishing by binding logins to specific domains using public-private key cryptography. In this case, attackers exploit a legitimate feature\u2014cross-device sign-in\u2014to trick victims into unknowingly authenticating malicious sessions.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/07\/21\/poisonseed-hackers-bypass-fido-keys-using-qr-phishing-and-cross-device-sign-in-abuse\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2025\/07\/poisonseed-hackers-bypass-fido-keys.html?m=1\">PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse<\/a><span class=\"screen-reader-text\">: PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed a novel attack technique that allows threat actors to bypass Fast IDentity Online (FIDO) key protections by deceiving users into approving authentication requests from spoofed company login portals. FIDO keys are hardware- or software-based authenticators designed to eliminate phishing by binding logins to specific domains using&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[40],"class_list":["post-703","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=703"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/703\/revisions"}],"predecessor-version":[{"id":704,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/703\/revisions\/704"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}