logo

New Passkey Attacks Explained: What Security Researchers Found This August

ID: 9a5198f5-7f9c-58df-9498-c9360d6f3930

STIX ID: report--9a5198f5-7f9c-58df-9498-c9360d6f3930

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Alex Poole

...
...

This report summarizes multiple passkey-focused security disclosures from Black Hat USA 2026 week: SpecterOps' 'Pass-the-Passkey' shows how Windows 11 WebAuthn assertions logged to the event log combined with Entra ID validation gaps enable replayed logins; Unit 42's 'Golden Pass-ta-key' extracts Chrome's security domain master secret for synced passkeys; and a Windows Hello for Business finding lets malware use a bound key without re-verification. The post outlines affected environments (Windows 11 endpoints, Microsoft Entra ID, Chrome synced passkeys), immediate mitigation (patch CVE-2026-34348, enforce server-side checks, monitor device identifiers), and architectural recommendations to decentralize key custody and add continuous identity assurance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.