logo

Flaws in Passkey Implementation Show Old Attacks Still Work

ID: 9f3914e5-85e0-5f63-9925-14deefd524d7

STIX ID: report--9f3914e5-85e0-5f63-9925-14deefd524d7

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: Arielle Waldman

...
...

SpecterOps research uncovered flaws in Windows 11 and Microsoft Entra ID that permitted replay/relay attacks against passkeys (coined “Pass-the-Passkey”), including a Windows Event Logging disclosure (CVE-2026-34348) and Entra ID validation issues that could let attackers impersonate privileged cloud identities and bypass phishing-resistant MFA; Microsoft has deployed mitigations and patched the Windows flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.