MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

This week in scams and cybersecurity news,
Passkeys are increasingly replacing passwords because they offer stronger protection against phishing and stolen credentials. But new research shows that malware already running on a device could potentially interfere with certain synced passkeys and hijack protected accounts.
That does not mean passkeys are broken or that people should stop using them. Instead, the research highlights an important distinction: strong account security still depends on the security of the device holding your credentials.
Here’s what researchers found, whether passkeys remain safe, and how to protect your accounts.
Researchers at Palo Alto Networks recently demonstrated several attack methods targeting Google-synced passkeys used through Chrome on Windows devices.
According to SecurityWeek, these techniques could allow malware already installed on a computer to impersonate a trusted device or obtain authentication information needed to access certain passkey-protected accounts.
The device must already be infected. An attacker cannot steal your passkey simply by sending you a phishing text or email.
The research focused on synced passkeys. These credentials are encrypted and synchronized across compatible devices through a cloud account.
Malware may be able to impersonate a trusted device. Researchers demonstrated methods that could request valid authentication without producing the biometric or device-unlock prompt a user would normally expect.
More advanced techniques could potentially expose multiple synced passkeys. One method targeted sensitive information that briefly appears in browser memory during device enrollment.
Google was notified and has reportedly introduced mitigations. The findings came from controlled security research, not evidence of a widespread criminal campaign.
Yes. Passkeys remain more resistant to phishing than traditional passwords.
Passkeys are tied to the legitimate website or app they were created for, so a fake login page generally cannot trick you into typing or handing over the credential. They also eliminate the risks created by weak and reused passwords.
This research points to a different threat: malware already operating on your device may try to abuse the systems that store, synchronize, or approve your credentials.
Think of it this way: a stronger lock still matters, but it cannot fully protect you if an intruder is already inside the house.
✓ Use passkeys when available. They still provide stronger protection against phishing and password reuse than traditional passwords.
✓ Keep your browser, operating system, and security software updated. Updates help close vulnerabilities that malware could exploit.
✓ Be cautious with unexpected files and downloads. Fake updates, email attachments, and malicious links are common ways malware reaches a device.
✓ Review your trusted devices and active sessions. Remove devices you no longer recognize or use.
Device security helps detect and block viruses, malware, and other threats that could compromise the device where your passkeys and passwords are stored.
Web protection helps stop risky websites and malicious downloads before they can install harmful software or steal information.
Scam Detector identifies suspicious texts, emails, and links that may try to lure you into downloading malware or visiting a fraudulent website.
Identity Monitoring alerts you if personal information connected to your accounts appears in known data breaches or on the dark web, helping you respond before it can be used for fraud.
Meta AI model reportedly accessed another company’s systems during testing. Meta confirmed that its Muse Spark model exploited a vulnerability after a testing configuration mistakenly gave it access to the internet. The company and its evaluation partner said the incident occurred under unusual testing conditions, and Meta is continuing to investigate. (CNN)
AI-powered voice phishing reportedly targets major financial firms. Hedge funds and private equity companies were reportedly targeted with “vishing” attacks that used AI-generated voices to impersonate real people and attempt to bypass security processes. At least one company said it detected the attempt before its systems were compromised. (Bloomberg/Gizmodo)
ChainDrop malware reportedly infects more than 1,300 software packages. Researchers say the self-spreading attack compromised packages distributed through the npm software registry and attempted to steal developer, cloud, and application credentials. Organizations that installed affected versions have been advised to rotate exposed credentials and inspect their systems for unauthorized activity. (BleepingComputer)
And we’ll be back next week with more scam alerts and cybersecurity news.
The post Can Malware Bypass Your Passkeys? This Week in Scams appeared first on McAfee Blog.

Have you ever visited a site that triggers a “your connection is not private” or “your connection is not secure” error message? Maybe you moved on. Or maybe you found yourself interested enough to continue anyway. Either way, understanding what the error means can keep you safer online. Knowing what the risks are and how you can clear up the error proves yet more important too.
Let’s take a look.
A “your connection is not private” error means that your browser can’t determine with certainty that a website has safe encryption protocols in place to protect your device and data. You can bump into this error on any device connected to the internet — a computer, smartphone, or tablet.
Note that the “your connection is not private” error is Google Chrome’s phrasing. Other browsers might use “your connection is not secure” or some variation of that as the warning message.
So, what exactly is going on when you see the “this connection is not private” error?
For starters, the error is only a warning. It doesn’t mean any of your private info is compromised. A “your connection is not private” error means the website you were trying to visit doesn’t have an up-to-date SSL (secure sockets layer) security certificate.
So, what’s an SSL? Think of it as a digital certificate that verifies the authenticity of a website. Further, it establishes an encrypted connection between your web browser and the website you’re visiting. As you can imagine, an SSL-protected site is vital when it comes to banking, shopping, or sending secure info online.
You can spot an SSL-protected site by an address that begins with HTTPS, with the “S” standing for “secure.” Many browsers also drop a little padlock symbol in the address bar to call it out. Some have a button in the bar that you can select to see if the site is protected.
Website owners must maintain the licensing regularly to ensure the site’s encryption capabilities are up to date. If a website’s SSL certificate is outdated, it means the site owners haven’t kept their encryption licensing current, but it doesn’t necessarily mean they’re up to no good. Even major websites have had momentary lapses that served up the message.
While it doesn’t always mean a website is unsafe to browse, pay attention. Using a site without an SSL connection might make your personal data less secure.
If you feel confident that a website or page is safe, despite the warning from your web browser, you can troubleshoot the issue a few ways:
Personal info like yours is valuable to hackers, so they take every chance they can to get their hands on it. Beyond sticking to visiting secure websites, you have several other ways you can protect yourself online.
The post What Does “Connection is Not Private” Mean? appeared first on McAfee Blog.