news.mlab.sh
Back to the feed
threat-intel

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

High
Image: The Hacker News
Summary

Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatures in cleartext, allowing attackers to chain those signatures with weaknesses in Microsoft Entra ID for privileged user impersonation. Unit 42 discovered malware could recover synced passkey private keys by exploiting Chrome's device identity machinery and a leaked Security Domain Secret. Additionally, a low-privilege process within a compromised Windows session can leverage a hardware-bound Windows Hello for Business key to generate fresh authentication material. These vulnerabilities highlight that passkeys are not a complete solution and require robust security practices beyond the authentication method itself.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.