FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Google Chrome Password Manager: Passkey Theft via UV Flag Exploitation

Research from Unit 42 reveals a critical implementation flaw in how Relying Parties (RPs) validate the 'User Verified' (UV) flag within WebAuthn ceremonies, enabling malware with standard user privileges on Windows to bypass biometric and PIN requirements. By exploiting the Chrome Google Password Manager Cloud Authenticator, attackers can execute a multi-stage attack—categorized as Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—to steal synced passkeys or the master key. This vulnerability degrades passkey-based multi-factor authentication (MFA) to a single-factor dependency on local host integrity, facilitating silent, non-interactive account takeovers without user interaction or physical prompts.

CISA Emergency Directive 26-01: Microsoft Entra ID MFA Bypass

CISA Emergency Directive 26-01 mandates the immediate remediation of a critical MFA bypass vulnerability in Microsoft Entra ID. Threat actors exploited the legacy Resource Owner Password Credentials (ROPC) OAuth 2.0 flow via the Azure CLI to conduct high-volume password spraying. This vector bypasses Conditional Access (CA) policies and MFA challenges by utilizing non-interactive authentication. Between June 12 and June 26, 2026, over 81 million login attempts were recorded, resulting in the compromise of 78+ accounts across 64 organizations. Immediate remediation requires the total disablement of the ROPC flow or its restriction to isolated service accounts to secure the cloud identity perimeter.

Kali365 Phishing Kit: MFA Bypass Targeting Microsoft 365, AWS, and Okta

The FBI has issued a critical alert regarding the Kali365 phishing kit, a sophisticated tool designed to compromise enterprise cloud environments. Utilizing Adversary-in-the-Middle (AiTM) techniques, the kit intercepts authentication traffic to harvest credentials and steal active session tokens, effectively bypassing multi-factor authentication (MFA) protocols. The campaign specifically targets Microsoft 365 (Outlook, Teams, OneDrive), Amazon Web Services (AWS), and Okta identity providers. Successful exploitation grants threat actors deep access to corporate communications and critical cloud infrastructure, enabling large-scale data exfiltration and the compromise of organizational identity management systems.

Adaptive Phishing Kits and BlueKit Browser-in-the-Middle BitM Frameworks

Modern phishing campaigns are deploying adaptive kits that utilize client-side JavaScript fingerprinting (User-Agent, OS, screen resolution) to serve device-specific HTML/CSS templates, increasing social engineering success rates. These kits employ Browser-in-the-Middle (BitM) frameworks, such as BlueKit, and OAuth/OIDC Device Code phishing to intercept real-time session cookies and MFA tokens, effectively bypassing traditional multi-factor authentication. Attackers utilize DNS query manipulation and environment-aware checks to evade automated sandboxes and security crawlers. The impact is a significant reduction in MFA efficacy and increased detection difficulty for legacy indicator-based security tools.

Evolution of Chinese PhaaS: Darcula UNC5814 and YY Lai Yu Transition to OTP Interception and Digital Wallet Tokenization

Chinese-language Phishing-as-a-Service (PhaaS) platforms, specifically Darcula (operated by UNC5814) and YY Lai Yu, have evolved from simple credential harvesting to sophisticated automated financial fraud. These platforms utilize real-time Man-in-the-Middle (MitM) modules to intercept One-Time Passcodes (OTP), effectively neutralizing traditional Multi-Factor Authentication (MFA). Furthermore, the integration of digital wallet tokenization engines allows attackers to convert stolen payment card data into mobile wallet tokens. This technical shift enables the execution of transactions that mimic legitimate, pre-authorized mobile wallet payments, successfully bypassing legacy fraud detection systems that monitor raw credit card numbers.


LINK COPIED TO CLIPBOARD