CybersecurityAugust 30, 2026· via Security Affairs

Weekly security roundup: passkeys under siege, ransomware hits governments

Weekly security roundup: passkeys under siege, ransomware hits governments

Image : Security Affairs

This week’s cybersecurity roundup spotlights fresh attacks on identity systems, ransomware groups meddling in politics, and a growing catalog of exploited flaws. From Google passkeys hijacked by phishing to Berlin’s government data offered for sale, threat actors are diversifying tactics while defenders scramble to keep pace.

When identity tools become attack vectors

A new phishing kit dubbed iAuthFlow v2 can bypass Google’s passkey reset protections, enrolling its own malicious credentials and maintaining persistence even after users reset passwords. Security researchers note the tool’s modular design and use of cryptographic context injection raise the bar for credential theft. Meanwhile, WhatsApp rolled out stronger security as passkeys surpassed one billion activations, highlighting the dual-edged nature of convenience-focused authentication.

Governments in the crosshairs

The Rhysida ransomware group claimed responsibility for breaching Berlin’s city government systems days before local elections, offering stolen data for auction. Separately, Philippine nuclear and naval entities were reportedly hit by a suspected Chinese state operator, while a UK airport operator disclosed an attack exposing 8.7 million customer records across three terminals. These incidents underscore how ransomware and espionage increasingly overlap in politically sensitive environments.

CISA’s expanding hit list

The U.S. Cybersecurity and Infrastructure Security Agency added multiple flaws to its Known Exploited Vulnerabilities catalog, including maximum-severity Oracle and Red Hat issues. Affected products range from the Linux kernel and JFrog Artifactory to Citrix NetScaler, signaling that legacy and supply-chain components remain prime targets. Water utilities also received fresh guidance to locate exposed programmable logic controllers before attackers do.

Why it matters

The surge in passkey-focused phishing and ransomware targeting elections reveals a shift toward identity infrastructure as the new perimeter. Organizations must treat every authentication tool as a potential attack surface and prioritize patching cycles that match today’s accelerated exploit timelines. Meanwhile, governments face the dual challenge of securing critical infrastructure while preventing adversaries from weaponizing data leaks during sensitive periods.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home