SOLUTION BRIEF
Not all MFA is created equal: Mobile MFA lures cybercriminals
Learn about the pitfalls of mobile MFA and best practices to stop account takeovers.

Legacy MFA such as mobile authentication is highly vulnerable to phishing and other forms of account takeovers. Learn about the pitfalls of mobile MFA and best practices to stop account takeovers.
OpenAI’s Advanced Account Security program: Top 5 things Codex users need to know The industry often speaks about “moving at the speed of AI” – a concept that presents two conflicting sides of the same coin. While global AI adoption empowers defenders to identify and remediate vulnerabilities faster than ever, it simultaneously arms attackers with sophisticated tools to exploit digital infrastructure. As AI transitions from simple chatbots to […] Read more
YSA-2026-02 Security Advisory YSA-2026-02 – webauthn-server-core User Impersonation Published Date: 2026-05-12 Tracking IDs: YSA-2026-02 CVE: CVE-2026-46419 CVSS: 7.7 Summary A security update is available for the Yubico open-source software project webauthn-server-core to resolve a user impersonation vulnerability. No Yubico hardware is affected. In specific implementations, an attacker that has an existing account with a relying party […] Read more
New to OpenAI’s Advanced Account Security program? Here’s how to add your YubiKey to ChatGPT accounts As part of OpenAI’s Advanced Account Security (AAS) program, the company is making phishing-resistant passkeys available for ChatGPT users to secure their accounts. Yubico has partnered with OpenAI to deliver a custom 2-pack set of hardware security keys: the YubiKey C NFC – OpenAI and YubiKey C Nano – OpenAI. YubiKeys are an important component […] Read more