Google Authenticator: The Hidden Mechanisms of Passwordless Authentication
2026-03-24T08:51:41Z•32aef8b6c57b5d7cde225b2fc39aaa80a3cf9c5494f0d705305bf12bdeeb9a45
AI agentsAI in malwareBoggy SerpensCL-UNK-1068CVE-2026-0628China espionageChromeGeminiGoogle AuthenticatorHandala HackIranian threat actorsLLM securityVoid Manticoreagentic AIauthenticationindirect prompt injectionkey managementnation-statepasskeyspasswordlessprompt fuzzingprompt injectionretail fraudvulnerability management','patching','OT security','edge defensewiper malware
What happened
Collection of Unit 42 research and blog posts (Mar 2026) covering: Google Authenticator/passkey architecture and secure key management; growing risks from agentic AI and LLMs (prompt injection, indirect web-based injection, prompt-fuzzing/guardrail bypass); current and emerging uses of AI in malware; multiple nation‑state and cybercrime threat assessments (Boggy Serpens, Iran-linked groups including Handala Hack/Void Manticore, suspected China-based espionage, CL-UNK-1068) with increased wiper and credential-theft activity; OT/IT edge defense guidance; and a high‑severity Chrome vulnerability—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 32aef8b6c57b5d7cde225b2fc39aaa80a3cf9c5494f0d705305bf12bdeeb9a45
- Enrichment time
- 2026-03-24T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.