{"id":11463,"date":"2025-07-21T12:33:21","date_gmt":"2025-07-21T05:33:21","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11463"},"modified":"2026-06-25T10:00:01","modified_gmt":"2026-06-25T03:00:01","slug":"its-not-the-vulnerability-its-the-feature-that-opened-up-to-the-attacker","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/21\/its-not-the-vulnerability-its-the-feature-that-opened-up-to-the-attacker\/","title":{"rendered":"It&#8217;s not the vulnerability, it&#8217;s the feature that opened up to the attacker."},"content":{"rendered":"<p><b>A new attack technique has been discovered, allowing the hacker group PoisonSeed to bypass the protection mechanism of the FIDO security key which is considered the &#8220;gold standard&#8221; in non-password authentication and anti-phishing today. The speciality of this technique lies not in exploiting the vulnerability in the FIDO protocol but in the way the attacker takes advantage of the legitimate feature: the cross-device sign-in mechanism.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1753079507535.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753079507535-png.17343\/\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753079507535.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753079507535-png.17343\/\" alt=\"1753079507535.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<p>\u200b<\/p>\n<\/div>\n<h3>The nature of the attack<\/h3>\n<p>The cross-device sign-in feature allows users to authenticate a login on one device (e. g., a desktop computer) using another device (such as a phone containing a FIDO key). This is a convenient method, but opens up a security blind spot in the context of users being unable to directly verify the domain that is requesting authentication.<\/p>\n<p><b>The attack sequence is as follows:<\/b><\/p>\n<ol>\n<li data-xf-list-type=\"ol\">The attacker sends a phishing email, luring the user to access a fake login gateway (e. g., Okta forgery).<\/li>\n<li data-xf-list-type=\"ol\">The user enters a username and password into the fake page.<\/li>\n<li data-xf-list-type=\"ol\">The login information is passed implicitly to the real login page.<\/li>\n<li data-xf-list-type=\"ol\">The real login page responds by generating a QR code for inter-device authentication.<\/li>\n<li data-xf-list-type=\"ol\">This QR code is passed back to the user on a fake interface.<\/li>\n<li data-xf-list-type=\"ol\">When a user scans a QR code with a mobile authentication app, they have inadvertently authenticated a login session created by the attacker, resulting in account access being seized.<\/li>\n<\/ol>\n<p>In essence, the user is authenticating a session that is not theirs, but still believes the process is legitimate.<\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1753079519842.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753079519842-png.17344\/\"><img decoding=\"async\" class=\"bbImage\" title=\"1753079519842.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753079519842-png.17344\/\" alt=\"1753079519842.png\" width=\"728\" height=\"428\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<h3>Why is this technique so dangerous?<\/h3>\n<p>This is a typical example of downgrade authentication, which is downgrading the authentication process to a form that is easily manipulated, even though the technology is modern and safe.<\/p>\n<p><b>Notable points:<\/b><\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Penetrate the FIDO protection even though we&#8217;re not exploiting any technical vulnerabilities.<\/li>\n<li data-xf-list-type=\"ul\">Taking advantage of the legal feature is almost undetected by the surveillance system.<\/li>\n<li data-xf-list-type=\"ul\">When combined with the Adversary &#8211; in &#8211; the &#8211; Middle (AitM) model, attacks become more difficult to detect.<\/li>\n<li data-xf-list-type=\"ul\">The attacker can then assign his own FIDO key to the victim&#8217;s account, disabling the real user&#8217;s ability to recover it.<\/li>\n<\/ul>\n<p>Up to now, there has been no specific record of organizations or users in Vietnam becoming victims of the campaign. However, the PoisonSeed attack group has deployed the technique on a global scale, leveraging CRM platforms and mass email systems to spread phishing links containing malicious QR codes.<\/p>\n<p>Therefore, organizations in Vietnam, especially those using platforms such as Okta, Google Workspace, Microsoft 365 or having implemented FIDO keys, should actively monitor and assess risks.<\/p>\n<p>Cybersecurity experts for organizations and businesses should also note:<\/p>\n<ol>\n<li data-xf-list-type=\"ol\">Not only implement FIDO but also make sure to configure the correct authentication domain to avoid false authentication.<\/li>\n<li data-xf-list-type=\"ol\">Restrict or disable inter-device login if not necessary, especially on sensitive accounts.<\/li>\n<li data-xf-list-type=\"ol\">Train users to identify phishing via QR codes and fake emails with authentication instructions.<\/li>\n<li data-xf-list-type=\"ol\">Set the alarm when a new FIDO key is added to the account.<\/li>\n<li data-xf-list-type=\"ol\">Protecting your entire account life cycle, including the password recovery phase, is a common weakness.<\/li>\n<\/ol>\n<p>WhiteHat&#8217;s point of view: This attack technique again shows that the security risk comes not only from software vulnerabilities but also from the way we design and use seemingly &#8220;innocent&#8221; features in our systems. The fact that a function such as inter-device login, which was designed to help users more conveniently, was used to bypass the FIDO key is a clear wake-up call.<\/p>\n<p>For security professionals, this is a reminder to take a look at the entire authentication architecture, especially how users interact with it in real life. No matter how powerful a system is, it can be defeated if the user authenticates the wrong login session or if the support features themselves become &#8220;open&#8221;.<\/p>\n<p>Monitoring behavior, responding quickly to irregularities, and questioning each feature is open to the user, which is never taken lightly.<\/p>\n<div style=\"text-align: right\"><b><i>The Hacker News<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong.18583\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong.18583\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new attack technique has been discovered, allowing the hacker group PoisonSeed to bypass the protection mechanism of the FIDO security key which is considered the &#8220;gold standard&#8221; in non-password authentication and anti-phishing today. The speciality of this technique lies not in exploiting the vulnerability in the FIDO protocol but in the way the attacker [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11463","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11463"}],"version-history":[{"count":1,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11463\/revisions"}],"predecessor-version":[{"id":11464,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11463\/revisions\/11464"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}