PoisonSeed, the notorious crypto-hacking attack group known for large-scale phishing campaigns, was seen cracking Fast Identity Online (FIDO) protections in a novel social engineering technique. In a campaign discovered by Expel, the infamous supply chain phishing attackers leveraged the cross-device sign-in feature available with FIDO keys. FIDO keys use hardware-based multi-factor authentication to address vulnerabilities…
