NCSC Backs Passkeys, Hailing a New Era of Sign-in
2026-04-23T08:52:16Z•23f4903627385a59c71cc7a8d09a772ab8144bff006b4f2aa3365a3b0a059c67
BlackCatFIDOGentlemen-ransomwareICS-security','Mirai','Formbook','DLL-side-loading','Android-malKelpDAOLOTLLazarusNCSCOTProxySmartQR-code-fraudRMM-abuseSilentGlassSystemBCUK-cyber-resilienceZionSiphonauthenticationfundingliving-off-the-landmacOSpasskeysphishingproxy-SIM-farmsransomwaresilent-subject-phishing
What happened
Infosecurity Magazine roundup highlights widespread shifts and active threats: the UK NCSC endorses passkeys (FIDO) and unveils SilentGlass hardware while the UK commits £90m to boost cyber resilience. Multiple active attacks and toolings are reported — critical nginx-ui MCP auth bypass (CVE-2026-33032) is being exploited, Mirai-style campaigns exploit TBK DVR command-injection (CVE-2024-3721) to build botnets, and ZionSiphon targets water OT/ICS. macOS living‑off‑the‑land (LOTL) techniques, mailbox‑rule abuse, Formbook with DLL side‑loading, a surge in silent-subject phishing (QR/RMM abuse),
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 23f4903627385a59c71cc7a8d09a772ab8144bff006b4f2aa3365a3b0a059c67
- Enrichment time
- 2026-04-23T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.