New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption
Security researchers have identified new attack vectors that target the software and cloud processes surrounding passkeys, rather than the underlying cryptography. These attacks require local access to a Windows endpoint to bypass MFA or steal credentials.
Three independent security investigations have exposed weaknesses in the systems surrounding passkeys, demonstrating how attackers with access to a Windows endpoint could impersonate users, bypass phishing-resistant multifactor authentication or recover the private keys behind cloud-synchronised credentials.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in