Security Uses Cryptography in Pieces. WinMagic Says That Gap Is What AI Attacks.
As AI-enabled attacks become faster and cheaper to launch, WinMagic CEO Thi Nguyen-Huu says organizations need to reduce the security decisions left to users and connect authentication more closely to the protected session that follows.
TORONTO, Sept. 30, 2026 /PRNewswire/ -- Artificial intelligence has changed the economics of cyberattacks, making convincing lures faster and cheaper to create. IBM reported in July that one in four malicious breaches was AI-enabled, costing organizations an average of about $6 million. Thi Nguyen-Huu, President and CEO of WinMagic, a cybersecurity company focused on endpoint authentication and encryption, points to adversary-in-the-middle (AitM) attacks as a threat he expects to become increasingly significant. In this scenario, the attacker sits between the user and the real service and relays the login as it happens.
Nguyen-Huu calls it the "mother of all attacks," one that can defeat login methods including passwords, one-time codes, push notifications, and passkeys without breaking them. He says there is nothing to patch or spot because both ends see a login that worked. All it needs is a convincing lure, which AI has made cheaper to create.
According to Proofpoint, almost half of the accounts taken over by attackers had multifactor authentication (MFA) turned on as of December 2024. "You can ask for more, check harder, verify again, none of it helps," Nguyen-Huu said. "Nothing in the exchange is false. The person is real, the device is real, and the answer to every question is correct."
The Rule the Industry Skipped
Nguyen-Huu's answer is one rule: authentication must produce a cryptographic key tied to the party the user is about to communicate with. Nothing in use for online access today does that. Today, a login typically ends with a verdict that the user has been authenticated, while the protected session that follows is established separately.
Machine-to-machine systems have used a version of this model for decades. Through mutual Transport Layer Security (mTLS), two systems can prove their identities while establishing a key protecting their communication. Extending it to people has traditionally required users to manage credentials themselves. Nguyen-Huu argues the endpoint should perform that work instead.
"Online, cryptography is the best defense we have. But humans cannot do cryptography," Nguyen-Huu said. "So the endpoint has to do it for us. You log in to your own device, and after that the device carries you everywhere online, proving a key on every connection. And it comes with something people may like more than the security: no user action at all."
What an Organization Can Deploy Today
WinMagic's MagicEndpoint applies that approach at login, authenticating both the user and device to an organization's existing identity provider. It has been tested with Microsoft Entra ID, Okta, and Ping without requiring changes to the applications users access. Instead of passwords, codes, or prompts, the device proves a hardware-protected key. The goal is to remove login decisions that can be manipulated while allowing the endpoint to handle the cryptographic work.
The next step is to shorten sessions. Most security teams know they should shorten them. Few do, because every extra sign-in lands on the user. With a device-bound key, it doesn't. The session renews silently. The gap between login and session is separate, and nobody has closed it. Short-lived assertions and stricter validation narrow that window, they do not eliminate it. "The login needs nobody else to move. The rest needs the industry to move with us," Nguyen-Huu said.
Closing the Gap Beyond the Login
The next phase will require the industry to take three practical steps:
The LIT project on GitHub includes a working reference implementation on Windows, and WinMagic shares additional source code, under agreement, with integration partners. The underlying flaw was published on the company's blog in February 2024, before the current acceleration of AI-enabled threats. Organizations interested in seeing the login implementation, as well as service providers interested in building the application side, can contact [email protected].
MagicEndpoint removes what a relay can harvest at the login and removes the prompt a relay needs in order to start. Nevertheless, it does not make an already-compromised device trustworthy, and an attacker relaying in real time at the exact moment a session is set up remains a risk that has to be tested, not assumed. Nguyen-Huu does not describe the approach as AI-proof or unphishable.
About WinMagic
WinMagic's mission is to secure the digital world through high standards and strong ethics. For nearly three decades, the organization has led innovation in encryption and endpoint security. Today, WinMagic is advancing a new paradigm for online access—anchoring the endpoint as the foundation of trust. By letting endpoints speak for users, WinMagic turns cumbersome logins into seamless, automated exchanges. What was once user-to-machine communication now becomes a machine-to-machine relationship, governed by policy and anchored in cryptography. This evolution eliminates friction, reduces risk, and lays the groundwork for the Secure Internet—where security is continuous, effortless, and requires no user action. Learn more at https://winmagic.com.
References:
Media Inquiries:
Karla Jo Helms
JOTO PR™
727-777-4629
jotopr.com
SOURCE WinMagic