Wednesday , June 3 2026
Passwordless

Microsoft New Accounts Go Passwordless By Default

Microsoft is focusing on eliminating password-based authentication, promoting passwordless sign-in and sign-up methods instead. For the past decade, Microsoft has allowed users to sign in using facial recognition, fingerprints, or a PIN with Windows Hello. Now, over 99% of users use this method to access their Windows devices, according to the company.

To allow users to sign into accounts without passwords, the industry created passkeys. These provide phishing-resistant authentication for any compatible app or website.

1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

A serious security flaw in Visual Studio Code’s webview lets attackers take GitHub OAuth tokens. This includes read/write access to...
Read More
1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

TP-Link Router Flaw Enables Remote Command Execution Attacks

TP-Link has revealed a serious security problem in its Archer BE450 and Archer BE7200 Wi-Fi routers. This flaw could let...
Read More
TP-Link Router Flaw Enables Remote Command Execution Attacks

ALERT
Google patches one exploited Android zero-day and 124 issues

Google has shared the June 2026 Android security updates to fix 124 flaws, including one zero-day issue used in special...
Read More
ALERT  Google patches one exploited Android zero-day and 124 issues

CISA warns two-year-old Oracle Vuln as actively exploited in attacks

CISA has given a new warning about a serious Oracle WebLogic Server flaw, named CVE-2024-21182, and added it to its...
Read More
CISA warns two-year-old Oracle Vuln as actively exploited in attacks

Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Many Instagram users lost access to their accounts because attackers tricked Meta's AI support tools into thinking they were the...
Read More
Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Anthropic confirms Claude Mythos-class models will be public

Anthropic has said it will release Mythos-class models to the public. They had to delay this because of security concerns...
Read More
Anthropic confirms Claude Mythos-class models will be public

Threat Actors Fake FIFA Sites to Steal Personal Info

The FBI warned people in a Public Service Announcement Alert I-052726-PSA on May 27, 2026, that bad actors are running...
Read More
Threat Actors Fake FIFA Sites to Steal Personal Info

CISA gives feds 4 days to fix cPanel plugin vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has told U.S. federal agencies to secure their servers in four days....
Read More
CISA gives feds 4 days to fix cPanel plugin vulnerability

ALERT
FortiClient EMS Code Execution Flaw Exploited to Deploy Malware

A recent phishing attack aimed at FortiClient Endpoint Management Server (EMS) has used trusted admin systems to quietly install a...
Read More
ALERT  FortiClient EMS Code Execution Flaw Exploited to Deploy Malware

Anthropic Unveils Free Security Plugin for Claude Code Terminal to Detect Flaws

Anthropic has released a tool that acts like a careful assistant in your terminal. This new security plugin for Claude...
Read More
Anthropic Unveils Free Security Plugin for Claude Code Terminal to Detect Flaws

As more users adopt passwordless authentication, attackers are focusing on accounts secured by passwords, using brute-force and phishing methods. Last year, Microsoft recorded over 7,000 password attacks every second.

“As passkeys become the new standard, expect increased pressure from cyberattackers on any accounts still protected by passwords or other phishable sign-in methods,” the company says.

Microsoft is now simplifying passwordless sign-ins for its services like Xbox and Copilot after introducing passkey support.

A simplified sign-in and sign-up user experience now streamlines and prioritizes passwordless authentication, while new Microsoft accounts now provide users with several passwordless options, eliminating the need to enroll a password.

Existing Microsoft users, the company says, can now delete their passwords from the account’s settings. Microsoft is now automatically detecting and setting the best sign-in method for users to prioritize safety.

“For example, if you have a password and ‘one time code’ set up on your account, we’ll prompt you to sign in with your one time code instead of your password. After you’re signed in, you’ll be prompted to enroll a passkey. Then the next time you sign in, you’ll be prompted to sign in with your passkey,” Microsoft explains.

Check Also

Terra Security

CVE-2026-25724
Terra Security researchers discovered Flaws in Anthropic’s Claude Code 

Terra Security shared results from recent tests that showed flaws in AI apps, agents, and …