logo

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

ID: 028563b2-dc35-55d7-9e9e-1862d92dddf1

STIX ID: report--028563b2-dc35-55d7-9e9e-1862d92dddf1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: Guru Baran

...
...

SpecterOps disclosed a "Pass-the-Passkey" family of attacks that exploit systemic WebAuthn implementation flaws—particularly Windows 11 logging of full WebAuthn assertions (CVE-2026-34348) and missing anti-replay validation in Microsoft Entra ID—enabling attackers with local or delegated access to harvest and replay assertions to bypass phishing-resistant MFA and impersonate privileged cloud accounts. The research details over 20 techniques (including API hooking, prompt flooding, UI-handle spoofing), supplies PoC utilities for assertion injection and log mining, and recommends patches, server-side replay protections, telemetry monitoring, and hardware-backed attestation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.