This day 02:04 06:04 10:04 14:05 18:05 22:05
Info  2026-08-03 14:05Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-08-03 — Passkeys aren't passwordless problems

Executive summary: A novel attack against passkey implementations reduces passwordless MFA to a single factor by exploiting relying parties that fail to validate the User Verified flag — a design gap that could undermine the industry's shift away from passwords. Meanwhile, automated doxing tools now assemble full personal profiles from leak data with zero OSINT skill, and Google quietly plans to exempt developers in sanctioned countries from Android verification, expanding the APK attack surface. On the analytical front, a column on dark patterns in vulnerability management metrics is worth a read for any team that dashboards its way into false security.


Top items


Themes

Authentication trust assumptions under pressure: The passkey finding joins a growing pattern this fortnight — from device-code phishing at industrial scale to Russia's SMS-only authentication mandate — where the industry is discovering that "passwordless" and "MFA" are not synonyms for "unphishable." The weak link is consistently implementation, not protocol.

Automation lowering the bar for offence: Doxing-as-a-service tools and the continued evolution of AI-assisted malware (per ESET's recent report) share the same trajectory: capabilities that required expertise six months ago now need only intent. Defensive playbooks that assume skilled adversaries may need recalibration for high-volume, low-skill attacks.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb