Yubico AB - Experts & Thought Leaders

Latest Yubico AB news & announcements

YubiKey 5.8: AI-Driven Secure Authentication Upgrade

Yubico, the pioneer of phishing-resistant authentication and creator of the original passkey, the YubiKey, today announced the general availability of its YubiKey 5.8 – marking an expansion of the role of the passkey from secure authentication to include verifiable, hardware-backed authorization. The new firmware delivers a foundation for secure enterprise workflows across identity wallets, document signing and AI-driven approvals, while also providing developers with the critical capabilities needed to test, design and deploy these next-generation security features early. Hardware-backed foundation As generative and agentic AI mature to drive rapid, automated cyber attacks, traditional multi-factor authentication (MFA) is failing to keep pace. Security leaders now face a challenge globally: securing not just who logs into a system, but exactly what actions a user or autonomous AI agent can perform. While the YubiKey has long delivered industry-pioneer defense against phishing, YubiKey 5.8 addresses the needs of complex, multi-environment enterprises – going beyond trusted logins to provide a secure, hardware-backed foundation for verifiable digital actions in the age of AI. “YubiKey 5.8 represents one of the most significant architectural updates to the modern authentication ecosystem by expanding phishing resistance into the workflows themselves,” said Albert Biketi, chief product and technology officer at Yubico. “In an era where AI agents execute high-consequence business workflows, organizations must enable dynamic verification of human intent. YubiKey 5.8 bridges that gap, bringing hardware-backed phishing resistance directly into digital signatures, enterprise credential management and human-in-the-loop validation workflows – without requiring costly custom cryptographic rollouts.” Custom cryptographic infrastructure The new firmware introduces support for the CTAP 2.3 standard while offering preview support for the emerging WebAuthn signing extension. Developers can now use familiar standards and APIs to build secure, privacy-preserving workflows without relying on expensive backend key management systems or custom cryptographic infrastructure. This significantly lowers the barrier to building trusted digital workflows, allowing developers to integrate high-assurance signatures into web applications, digital wallets and AI-driven workflow approval systems with greater speed and less complexity. The YubiKey 5.8 delivers substantial technical upgrades built directly for developers working across the modern enterprise identity control plane: Support for cutting-edge use cases: Enables hardware-backed digital signatures through standardized APIs – opening the door to document signing, identity wallets, workflow approvals, and other high-assurance transactions Better user experience and enterprise scale: Expanded Enterprise Attestation support to 16 Relying Party (RP) IDs on a single key. This allows a single YubiKey to be simultaneously uniquely identified down to an individual device across trusted development, testing, staging and production environments across multiple identity providers without compromising user privacy Simplified developer integration: Introduces CTAP 2.3 support and preview support for the emerging WebAuthn signing extensions and more, making it easier for developers to integrate secure digital signatures using familiar standards Emerging initiatives secured: Expands support for digital identity wallets, verifiable credentials with privacy-enabling algorithms, and Secure Payment Confirmation (SPC) support for those developing hardware-backed payment use cases on the web Streamlined user experience: Persistent PIN/UV auth tokens allow apps to enable frictionless credential discovery and selection, with more autofill capabilities and fewer PIN prompts for users Operational simplicity and lower overhead: Introduces autofill-like credential discovery directly alongside software passkeys. This reduces user confusion, accelerates phishing-resistant passkey adoption, and minimizes IT helpdesk enrollment costs Digital identity credentials “The new signing capabilities of YubiKey 5.8 are a game changer for digital identity and credentials,” said Leif Johansson, executive director at SIROS Foundation. “In the last decade, FIDO authentication has become the industry gold standard for phishing-resistant authentication. By adding signatures, a whole range of new applications become possible without introducing platform lock-in. At SIROS, we are working to integrate the new signing capabilities into a seamless framework for secure phishing-resistant, digital identity credentials.” YubiKey 5.8 is now shipping across all major YubiKey product lineups starting today. For organizations actively working on the next generation of use cases with a focus on hardware-backed signatures, digital wallet features and AI-based workflows, the YubiKey 5.8 enables acceleration of strong security for these scenarios. YubiKey 5.8 supports all of the capabilities of YubiKey 5.7.4 and expands the use of passkeys for enterprise use cases. At this time, the YubiKey FIPS Series will remain on the newly validated FIPS 140-3 firmware 5.7.4 to maintain regulatory alignment. The YubiKey CCN Series will also remain on 5.7.4 while it is undergoing final re-certification.

Yubico's Role In Advancing European Digital Identity

Yubico, the pioneer of phishing-resistant authentication and creator of the most secure hardware-backed passkey – the YubiKey – announces its official acceptance as a member of the European Cyber Security Organization (ECSO), a pan-European public-private federation focused on empowering European cybersecurity communities. The membership empowers both Yubico and ECSO to accelerate a shared commitment to advancing phishing-resistant authentication and modern digital identity standards across Europe. ECSO welcomes Yubico at a pivotal moment, as organizations across the continent – and globally – struggle to mitigate a massive wave of sophisticated credential-based attacks easily bypassing traditional passwords and legacy, phishable multi-factor authentication (MFA). As AI-driven phishing attacks targeting digital identities surged over 200 percent in Europe, this membership highlights Yubico's role as a trusted cybersecurity leader and innovator in digital identity protection throughout Europe. Global cybersecurity innovation “Welcoming Yubico to ECSO is a strong signal of where the European cybersecurity ecosystem is heading,” said Dr Joanna Świątkowska, secretary general at ECSO. “Their globally recognized expertise in authentication and identity protection reflects the level of innovation and excellence required to ensure Europe’s digital sovereignty. Yubico stands as a compelling proof point that Europe can be both secure and at the forefront of global cybersecurity innovation. Welcome to the Family!” While Yubico operates today as a global company supporting organizations in over 160 countries, it holds ongoing, longstanding deep roots in Europe. Founded in Sweden in 2007, the company maintains its European headquarters and significant engineering presence in Stockholm. Yubico continues its legacy of local manufacturing in Sweden, delivering European-made, high-assurance security solutions across the continent and beyond. Automated enterprise environments By partnering with ECSO, Yubico aims to expand its focus on building cyber resilient environments for European businesses, governments and critical infrastructure. The collaboration will focus heavily on education and best practices for accelerating the deployment of modern, hardware-backed passkeys like the YubiKey, eliminating insecure legacy MFA, and establishing strict accountability chains for automated enterprise environments. “Our alliance with ECSO marks a major milestone in Yubico’s mission to make the digital world safer for all,” said Jerrod Chong, chief executive officer at Yubico. “Stockholm, along with our presence in countries like France, Germany and the UK, continues to anchor our commitment to European security and digital sovereignty. We look forward to partnering closely with ECSO to help organizations scale passwordless authentication responsibly, close the identity verification gap, and firmly secure both human and non-human identities across the enterprise.” Phishing-resistant hardware passkeys Yubico’s integration into the ECSO community aligns with broader structural shifts in European cyber policy, including the expanding momentum around European Digital Identity (EUDI) wallets. Yubico continues to drive open identity standards globally and has recently pioneered efforts in the EU to ensure digital identity wallets are backed by non-syncable, phishing-resistant hardware passkeys. As European enterprises navigate tightening regulatory regimes and escalating automated threats, Yubico's role as an ECSO partner ensures that the cornerstone of modern security – verifiable human presence and touch – remains at the heart of the region's cyber defense strategy.

Enhance OpenAI Security With YubiKey Authentication

Yubico, the pioneer of phishing-resistant authentication and creator of the YubiKey – the gold standard of security keys – today announced an industry-first collaboration with OpenAI, the creator of ChatGPT. Beginning today, people can purchase a new two-pack set of custom YubiKeys as part of OpenAI’s Advanced Account Security program – enabling them to secure their ChatGPT accounts with security keys, containing the strongest hardware-backed passkeys. Highest level of protection Specifically designed for security-conscious users who are at increased risk of targeted digital attacks, the set includes a YubiKey C NFC for tap-to-authenticate on mobile, and a low-profile YubiKey C Nano that stays in the user’s port for everyday laptop use – both packed with modern authentication features for the highest level of protection. With OpenAI already using YubiKeys internally to protect its employees and infrastructure from sophisticated phishing, it is now bringing the same level of account security to its users. This partnership between two industry leaders elevates protection for OpenAI user accounts through proven phishing-resistant, hardware-backed authentication – helping reduce the risk of account takeovers and making secure login simple. Hardware-backed authentication “We are introducing a new model for phishing-resistant security at scale for the AI ecosystem,” said Jerrod Chong, chief executive officer, Yubico. “This partnership with OpenAI delivers the highest level of protection against phishing with a low-friction user experience. Ultimately, our intent is to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide. We are proud to partner with OpenAI to deliver YubiKeys – the leading security key that offers the strongest way to use passkeys – increasing protection of sensitive user data for the AI frontier.” Phishing-resistant protection “Security keys are one of the best ways to protect accounts from phishing, and Yubico has played a leading role in making that protection practical and accessible,” said Dane Stuckey, chief information security officer, OpenAI. “We’ve made YubiKeys a standard part of how we protect OpenAI employees, and with Advanced Account Security, we’re making it easier for ChatGPT users to choose that same kind of phishing-resistant protection when it’s right for them.” By combining Yubico's global scale and enterprise-grade reliability with OpenAI's commitment to user privacy and strong data security, this partnership expands the global adoption of YubiKeys – ensuring the future of AI is more secure against an evolving cyber threat landscape. Once enrolled, users benefit from the strongest account defense available today through a fast, passwordless experience. The YubiKey C NFC - OpenAI and YubiKey C Nano - OpenAI are available with exclusive pricing for existing OpenAI account holders.