LIVE · cybersecurity feed
Live wire
nation-state

The people who know passkeys best are still typing passwords

A recent survey of nearly 1,900 technology and security professionals across nine countries reveals that while 87% are familiar with passkeys, 43% still rely on usernames and passwords for work accounts. This preference for traditional authentication methods persists despite the known vulnerabilities associated with passwords and the respondents' high level of expertise in the field.

ZeroDay News ·

Source: Help Net Security

A recent survey of nearly 1,900 technology and security professionals across nine countries reveals that while 87% are familiar with passkeys, 43% still rely on usernames and passwords for work accounts. This preference for traditional authentication methods persists despite the known vulnerabilities associated with passwords and the respondents' high level of expertise in the field.

The survey, conducted by Yubico and Okta, highlights a significant disconnect between awareness of modern authentication methods and their adoption. A primary factor identified is the initial onboarding process: 52% of respondents were issued a username and password when they started their current roles, and these habits tend to persist. For personal accounts, these professionals also primarily use passwords, followed by text-message codes, which themselves carry risks like SIM-swapping attacks.

This continued reliance on legacy login practices leaves enterprises vulnerable to contemporary attack vectors, according to industry experts. Despite this, a majority of respondents rated their own organizations as secure, a perception that researchers attribute to an "optimism bias," where individuals believe their expertise protects them from adverse outcomes.

The survey also touched on the prevalence of phishing attacks. Forty-four percent of respondents reported that their organization had experienced at least one successful AI-driven phishing attack in the past year. However, this figure represents self-reported beliefs rather than verified breach rates, with a similar number reporting no such attacks and others unsure.

To further investigate susceptibility to phishing, researchers presented respondents with two HR emails announcing an updated employee handbook—one written by a person and one generated by AI—and asked them to identify the human-authored version. Only 36% correctly identified it. Most believed the AI had written the human-authored email, or were unsure, indicating the difficulty even careful readers have in discerning AI-generated content.

This finding underscores the limitations of human vigilance in detecting sophisticated phishing attempts. Phishing-resistant login methods, such as passkeys, shift the security check from human judgment to cryptographic keys that verify a site's domain, preventing the transmission of valid credentials even if an employee is fooled.

To improve security posture, Yubico and Okta recommend issuing phishing-resistant authenticators to new hires during onboarding, ensuring strong authentication from the outset. They also advocate for enforcing these methods through application sign-on policies, implementing device health checks before sessions begin, and conducting ongoing risk assessments. This includes requiring a key touch or biometric scan before an AI agent performs tasks on an individual's behalf.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…

patch

How AI can fix cybersecurity compliance: From dashboards to continuous execution

Cybersecurity compliance, a critical but often costly endeavor, is increasingly challenged by the rapid pace of cyber threats and the manual nature of traditional compliance processes. The Department of War's recent suspension of Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, which would have mandated third-party assessments for contractors handling controlled…

ransomware

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's official Twitter account, which boasts 13 million followers, was reportedly compromised by an attacker who used the platform to promote a cryptocurrency scam. The incident, which occurred on October 8, 2026, involved the attacker posting an image of Clippy, Microsoft's former animated assistant, alongside a promotion for a "dodgy crypto coin."

ransomware

Ransomware recovery CEO charged over secret ransom payments

The owner of MonsterCloud, a ransomware remediation company, has been charged with allegedly defrauding clients by secretly paying ransoms to cybercriminals while claiming to use proprietary technology for data recovery. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026, and arraigned…

security

Cisco quantum network controller lets apps order entanglement on demand

Cisco has unveiled a Quantum Network Controller, a research prototype designed to enable applications to request entanglement on demand from a quantum network, abstracting away the underlying hardware complexities. This controller manages the distribution of entanglement, a linked quantum state shared between distant points, which is a critical resource for quantum networks.

breach

Evolution of Web3 in Cloud Supply Chain Attacks

Threat actors are increasingly leveraging Web3 technologies, including smart contracts and blockchain networks, to enhance their command-and-control (C2) infrastructure in cloud supply chain attacks. This evolution allows for dynamic updates to botnets and worm networks through single smart contract transactions, bypassing traditional Web 2.0-style network monitoring and making C2…