New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

2026-08-10T13:24:01Z56b732a28f2bbe1b6210e5923bc8d1db114129d1f114db82ac3d74d832624831
CVE-2026-64561CVE-2026-64638CVE-2026-8037AiTMCSS injectionKVM escapeMFA bypassRATVS Code extensionsactive exploitationcloud securitycontainer escapecredential theftdata exfiltrationidentity attacksinfostealermalwarenpmpasskeysphishingprivilege escalationprompt injectionremote code executionsupply-chain attackvishingvulnerabilitywebmailzero-day

What happened

A security-news feed covering active exploitation, zero-days, malware and supply-chain campaigns, phishing and identity attacks, AI-agent abuse, webmail attacks, and significant vulnerabilities across Metabase, Kemp LoadMaster, WordPress, Linux, KVM, Cisco, TrueConf, and other platforms. Multiple reports describe in-the-wild exploitation and credential or data theft, including a CVSS 10 Metabase zero-day, CVE-2026-8037 in Kemp LoadMaster, and CVE-2026-64638 in WordPress.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
56b732a28f2bbe1b6210e5923bc8d1db114129d1f114db82ac3d74d832624831
Enrichment time
2026-08-10T13:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.