Flaws in Passkey Implementation Show Old Attacks Still Work
ID: 9f3914e5-85e0-5f63-9925-14deefd524d7
STIX ID: report--9f3914e5-85e0-5f63-9925-14deefd524d7
Feed Name: Dark Reading
Threat Score
SpecterOps research uncovered flaws in Windows 11 and Microsoft Entra ID that permitted replay/relay attacks against passkeys (coined “Pass-the-Passkey”), including a Windows Event Logging disclosure (CVE-2026-34348) and Entra ID validation issues that could let attackers impersonate privileged cloud identities and bypass phishing-resistant MFA; Microsoft has deployed mitigations and patched the Windows flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
