New Passkey Attacks Explained: What Security Researchers Found This August
ID: 9a5198f5-7f9c-58df-9498-c9360d6f3930
STIX ID: report--9a5198f5-7f9c-58df-9498-c9360d6f3930
Feed Name: Security Boulevard
This report summarizes multiple passkey-focused security disclosures from Black Hat USA 2026 week: SpecterOps' 'Pass-the-Passkey' shows how Windows 11 WebAuthn assertions logged to the event log combined with Entra ID validation gaps enable replayed logins; Unit 42's 'Golden Pass-ta-key' extracts Chrome's security domain master secret for synced passkeys; and a Windows Hello for Business finding lets malware use a bound key without re-verification. The post outlines affected environments (Windows 11 endpoints, Microsoft Entra ID, Chrome synced passkeys), immediate mitigation (patch CVE-2026-34348, enforce server-side checks, monitor device identifiers), and architectural recommendations to decentralize key custody and add continuous identity assurance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
