Pass-ta-Key: When Synced Passkeys Trust a Compromised Host
Unit 42’s Pass-ta-key research exposes device-trust and recovery attacks around Google-synced passkeys. Trace the mechanics, detection, and defensive choices.
Unit 42’s Pass-ta-key research exposes device-trust and recovery attacks around Google-synced passkeys. Trace the mechanics, detection, and defensive choices.
Technical analysis of enterprise AI attack chains: indirect prompt injection, memory poisoning, tool abuse, MCP exposure, and detection.
Advanced guide to AI threat modeling for RAG, agents, and MCP, with trust boundaries, context provenance, and identity separation.
MCP Security in practice: a safe lab with fictional documents, a mocked local agent, controlled tool exploitation, permissions, schemas, and auditable logs.