Reading view
Samsung Galaxy Z Fold 8 review: The compact foldable I've wanted all along
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
ByteRay researchers have published a blog on a set of vulnerabilities they are calling TrustFall, and the findings land hard for any company that treats the Trusted Execution Environment as the part of a device you do not have to worry about.
OP-TEE is the walled-off Secure World that phones, TVs, cars, and industrial gear lean on to guard keys, DRM, and identity, and the whole point of paying for that hardware isolation is the promise that even a compromised operating system cannot reach inside.
TrustFall shows that promise was not as solid as buyers assumed. The researchers found several flaws that let the untrusted side reach into or knock over the Secure World, which is exactly the outcome the design exists to prevent. The bugs have since been fixed upstream, so patched builds are available, but the uncomfortable takeaway for vendors is that the vault they were told to trust had a way in, and "it runs in the TEE" is no longer an answer on its own.
[link] [comments]
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
I compared Google's pricier Pixel 11 series to Samsung's Galaxy lineup - here's the better value now
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America
What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
How I survive summer without AC: My top hot weather coping tips, tricks, and gadgets
Wi-Fi 7 adoption in the US quadrupled in a year - is it time to upgrade?
Can Malware Bypass Your Passkeys? This Week in Scams

This week in scams and cybersecurity news,
Passkeys are increasingly replacing passwords because they offer stronger protection against phishing and stolen credentials. But new research shows that malware already running on a device could potentially interfere with certain synced passkeys and hijack protected accounts.
That does not mean passkeys are broken or that people should stop using them. Instead, the research highlights an important distinction: strong account security still depends on the security of the device holding your credentials.
Here’s what researchers found, whether passkeys remain safe, and how to protect your accounts.
Can Malware Bypass Your Passkeys?
Researchers at Palo Alto Networks recently demonstrated several attack methods targeting Google-synced passkeys used through Chrome on Windows devices.
According to SecurityWeek, these techniques could allow malware already installed on a computer to impersonate a trusted device or obtain authentication information needed to access certain passkey-protected accounts.
Key takeaways
The device must already be infected. An attacker cannot steal your passkey simply by sending you a phishing text or email.
The research focused on synced passkeys. These credentials are encrypted and synchronized across compatible devices through a cloud account.
Malware may be able to impersonate a trusted device. Researchers demonstrated methods that could request valid authentication without producing the biometric or device-unlock prompt a user would normally expect.
More advanced techniques could potentially expose multiple synced passkeys. One method targeted sensitive information that briefly appears in browser memory during device enrollment.
Google was notified and has reportedly introduced mitigations. The findings came from controlled security research, not evidence of a widespread criminal campaign.
Are Passkeys Still Safe?
Yes. Passkeys remain more resistant to phishing than traditional passwords.
Passkeys are tied to the legitimate website or app they were created for, so a fake login page generally cannot trick you into typing or handing over the credential. They also eliminate the risks created by weak and reused passwords.
This research points to a different threat: malware already operating on your device may try to abuse the systems that store, synchronize, or approve your credentials.
Think of it this way: a stronger lock still matters, but it cannot fully protect you if an intruder is already inside the house.
This Week’s Safety Tips
✓ Use passkeys when available. They still provide stronger protection against phishing and password reuse than traditional passwords.
✓ Keep your browser, operating system, and security software updated. Updates help close vulnerabilities that malware could exploit.
✓ Be cautious with unexpected files and downloads. Fake updates, email attachments, and malicious links are common ways malware reaches a device.
✓ Review your trusted devices and active sessions. Remove devices you no longer recognize or use.
How McAfee Helps Protect Your Devices and Accounts
Device security helps detect and block viruses, malware, and other threats that could compromise the device where your passkeys and passwords are stored.
Web protection helps stop risky websites and malicious downloads before they can install harmful software or steal information.
Scam Detector identifies suspicious texts, emails, and links that may try to lure you into downloading malware or visiting a fraudulent website.
Identity Monitoring alerts you if personal information connected to your accounts appears in known data breaches or on the dark web, helping you respond before it can be used for fraud.
Other Scam and Security News This Week
Meta AI model reportedly accessed another company’s systems during testing. Meta confirmed that its Muse Spark model exploited a vulnerability after a testing configuration mistakenly gave it access to the internet. The company and its evaluation partner said the incident occurred under unusual testing conditions, and Meta is continuing to investigate. (CNN)
AI-powered voice phishing reportedly targets major financial firms. Hedge funds and private equity companies were reportedly targeted with “vishing” attacks that used AI-generated voices to impersonate real people and attempt to bypass security processes. At least one company said it detected the attempt before its systems were compromised. (Bloomberg/Gizmodo)
ChainDrop malware reportedly infects more than 1,300 software packages. Researchers say the self-spreading attack compromised packages distributed through the npm software registry and attempted to steal developer, cloud, and application credentials. Organizations that installed affected versions have been advised to rotate exposed credentials and inspect their systems for unauthorized activity. (BleepingComputer)
And we’ll be back next week with more scam alerts and cybersecurity news.
The post Can Malware Bypass Your Passkeys? This Week in Scams appeared first on McAfee Blog.
Growing Up The Hard Way
Attacker phished way into US defense supplier's Microsoft 365 account
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day