The Yubico Validation Server contains a pair of vulnerabilities, one of which allows the replay of one-time passwords.
A review of the SoloKey firmware found a serious downgrade attack flaw, which an attacker could use to install an older, vulnerable version. The bug has been fixed.
OpenSSH has added support for hardware security keys that implement the U2F standard.
A proposal that would standardize the format of SMS messages being used in two-factor authentication schemes has a simple goal: make users relying on those one-time passcodes less susceptible to phishing attacks.
Mozilla will soon require add-on developers to enable 2FA for their accounts in an effort to defeat supply chain attacks.