downgrade – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 20 Jul 2025 14:36:11 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 downgrade – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/ https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/#respond Sun, 20 Jul 2025 14:36:11 +0000 https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/

Hacker

A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals.

The PoisonSeed threat actors are known to employ large-volume phishing attacks for financial fraud. In the past, distributing emails containing crypto seed phrases used to drain cryptocurrency wallets.

In the recent phishing attack observed by Expel, the PoisonSeed threat actors do not exploit a flaw in FIDO2’s security but rather abuse the legitimate cross-device authentication feature.

Cross-device authentication is a WebAuthn feature that allows users to sign in on one device using a security key or authentication app on another device. Instead of requiring a physical connection, such as plugging in a security key, the authentication request is transmitted between devices via Bluetooth or a QR code scan.

The attack begins by directing users to a phishing site that impersonates corporate login portals, such as from Okta or Microsoft 365.

When the user enters their credentials into the portal, the campaign uses an adversary-in-the-middle (AiTM) backend to silently log in with the submitted credentials on the legitimate login portal in real-time.

The user targeted in the attack normally would use their FIDO2 security keys to verify multi-factor authentication requests. However, the phishing backend instead tells the legitimate login portal to authenticate using cross-device authentication.

This causes the legitimate portal to generate a QR code, which is transmitted back to the phishing page and displayed to the user.

When the user scans this QR code using their smartphone or authentication app, it approves the login attempt initiated by the attacker.

PoisonSeed attack flow to bypass FIDO2 protections
PoisonSeed attack flow to bypass FIDO2 protections
Source: Expel

This method effectively bypasses FIDO2 security key protections by allowing attackers to initiate a login flow that relies on cross-device authentication instead of the user’s physical FIDO2 key.

Expel warns that this attack does not exploit a flaw in the FIDO2 implementation, but instead abuses a legitimate feature that downgrades the FIDO key authentication process.

To mitigate the risk, Expel recommends the following defenses:

  • Limiting geographic locations from which users are allowed to log in and establishing a registration process for individuals traveling.
  • Routinely check for the registration of unknown FIDO keys from unknown locations and uncommon security key brands.
  • Organizations can consider enforcing Bluetooth-based authentication as a requirement for cross-device authentication, which significantly reduces the effectiveness of remote phishing attacks.

Expel also observed a separate incident where a threat actor registered their own FIDO key after compromising an account via what is believed to be phishing and resetting the password. However, this attack did not require any methods to trick the user, like a QR code.

This attack highlights how threat actors are finding ways to bypass phishing-resistant authentication by tricking users into completing login flows that bypass the need for physical interaction with a security key.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/feed/ 0 48711
Moody’s historic downgrade of US credit system could add fuel to Bitcoin safe-haven status https://earlybirdsinvest.com/moodys-historic-downgrade-of-us-credit-system-could-add-fuel-to-bitcoin-safe-haven-status/ https://earlybirdsinvest.com/moodys-historic-downgrade-of-us-credit-system-could-add-fuel-to-bitcoin-safe-haven-status/#respond Sat, 17 May 2025 05:48:21 +0000 https://earlybirdsinvest.com/moodys-historic-downgrade-of-us-credit-system-could-add-fuel-to-bitcoin-safe-haven-status/

Moody’s downgraded the United States’ long-term credit rating from Aaa to Aa1 on May 16, marking the first time in history the agency has stripped the US of its top-tier status.

The agency pointed to a decade of rising debt levels, escalating interest burdens, and a consistent failure by policymakers to enact meaningful deficit controls.

According to Moody’s, federal deficits are expected to widen sharply in the coming years, potentially reaching 9% of GDP by 2035, up from 6.4% in 2024, as spending commitments grow and interest costs consume more of the federal budget.

While Moody’s affirmed a “stable” outlook for now, citing the dollar’s reserve currency status and the scale of US financial markets, the downgrade marks a symbolic fracture in global perceptions of US creditworthiness.

The move follows prior cuts by S&P in 2011 and Fitch in 2023, leaving the US with no top-tier rating for the first time in modern financial history.

Market reaction was modest, with Treasury yields edging higher. However, the longer-term implications, especially for institutional portfolios built on the assumption of US risk-free debt, may ripple outward over time.

Bitcoin stays firm amid sovereign credit shake-up

Bitcoin (BTC) maintained its position above $100,000 amid the sustained macro uncertainty, highlighting its emerging status as a non-sovereign hedge against fiscal instability.

Based on CryptoSlate data, Bitcoin was trading at $103,591 as of press time, up 0.15% over the past 24 hours. Meanwhile, many of the major altcoins saw some downward selling pressure and volatility following the news.

Bitcoin and equities showed resilience the last time the US faced a rating cut in 2023. The pattern may repeat, but the market remains cautious of potential selling on Monday’s open.

The flagship crypto’s resilience contrasts with the historical view of cryptocurrencies as risk-on assets, suggesting a growing investor base now treats Bitcoin as a strategic allocation during macroeconomic uncertainty.

Many in the industry see Bitcoin’s price stability following the downgrade as further evidence that its safe-haven narrative is gaining traction among investors.

With centralized monetary systems facing credibility challenges, capital appears increasingly open to decentralized alternatives backed by code, scarcity, and network effects rather than government promises.

Bitcoin Market Data

At the time of press 1:32 am UTC on May. 17, 2025, Bitcoin is ranked #1 by market cap and the price is down 0.47% over the past 24 hours. Bitcoin has a market capitalization of $2.05 trillion with a 24-hour trading volume of $44.97 billion. Learn more about Bitcoin ›

Crypto Market Summary

At the time of press 1:32 am UTC on May. 17, 2025, the total crypto market is valued at at $3.28 trillion with a 24-hour volume of $110.11 billion. Bitcoin dominance is currently at 62.50%. Learn more about the crypto market ›

]]>
https://earlybirdsinvest.com/moodys-historic-downgrade-of-us-credit-system-could-add-fuel-to-bitcoin-safe-haven-status/feed/ 0 36687