Google Authenticator: The Hidden Mechanisms of Passwordless Authentication

2026-03-24T08:51:41Z32aef8b6c57b5d7cde225b2fc39aaa80a3cf9c5494f0d705305bf12bdeeb9a45
AI agentsAI in malwareBoggy SerpensCL-UNK-1068CVE-2026-0628China espionageChromeGeminiGoogle AuthenticatorHandala HackIranian threat actorsLLM securityVoid Manticoreagentic AIauthenticationindirect prompt injectionkey managementnation-statepasskeyspasswordlessprompt fuzzingprompt injectionretail fraudvulnerability management','patching','OT security','edge defensewiper malware

What happened

Collection of Unit 42 research and blog posts (Mar 2026) covering: Google Authenticator/passkey architecture and secure key management; growing risks from agentic AI and LLMs (prompt injection, indirect web-based injection, prompt-fuzzing/guardrail bypass); current and emerging uses of AI in malware; multiple nation‑state and cybercrime threat assessments (Boggy Serpens, Iran-linked groups including Handala Hack/Void Manticore, suspected China-based espionage, CL-UNK-1068) with increased wiper and credential-theft activity; OT/IT edge defense guidance; and a high‑severity Chrome vulnerability—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
32aef8b6c57b5d7cde225b2fc39aaa80a3cf9c5494f0d705305bf12bdeeb9a45
Enrichment time
2026-03-24T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google Authenticator: The Hidden Mechanisms of Passwordless Authentication · Baitaphish