New Attacks Can Bypass 'Unphishable' Passkey Security
Many third-party Windows password managers now keep passkeys in end-to-end encrypted cloud blobs because malware can access local app data, developers said.
9 Articles
9 Articles
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Last week a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative over password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe t…
Replays, Master Keys, and Silent Prompts: Unpacking the Hidden Infrastructural Flaws Behind FIDO2
I've spent the last few years telling friends and family the same thing: switch to passkeys, they can't be phished. That advice wasn't wrong exactly, but reading through this new research left me a little humbled. Three separate teams just showed that you don't need to break FIDO2's cryptography to beat it. You just need to find the messy human infrastructure sitting around it, a logging service that kept too much, a memory buffer that lingered …
Microsoft Passkey: How to Opt Out
Microsoft expert: delay Passkeys rollout with a Graph beta opt out via Entra Auth Admin to buy migration time Passkey opt-out: Use the single Microsoft Graph command passkeyDynamicMigration to pause Microsoft’s September passkey rollout for your tenant. This step delays user registration prompts but does not cancel the overall migration timeline. Key dates: API support available from 2026-08-01, rollout starts 2026-09-01, and Microsoft-provided…
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security even when cryptographic private keys remain securely stored inside hardware tokens or trusted enclaves. SpecterOps research highlights three core vulnerabilities across the WebAuthn ecosystem and over 20 distinct attack techniques impacting Windows 11, Microsoft Entra ID, web browsers, password m…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




