Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using Microsoft Entra ID, Windows Hello, and Google Chrome Passkeys
Incident: Discovery of multiple vulnerabilities allowing the bypass or recovery of passkey-based authentication.
Impact: Attackers can impersonate privileged users or steal synced private keys, negating the phishing-resistance of passkeys.
Attacker: Security researchers (SpecterOps, Unit 42, and Dirk-jan Mollema)
Analysis: Researchers identified three distinct paths to bypass passkey security: reusing signed material in Windows, extracting keys from Google Password Manager, and abusing active Windows Hello sessions. These flaws demonstrate that implementation errors can override the cryptographic strengths of FIDO2/Passkey standards. The vulnerabilities allow for unauthorized impersonation and private key recovery without breaking the underlying encryption.
Recommendations: Apply Microsoft security updates immediately, specifically addressing CVE-2026-34348.; Implement a Zero Trust architecture and least-privilege access to limit the impact of session hijacking.; Enhance endpoint security to prevent malware from leveraging active hardware-bound authentication sessions.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source