
Pass-the-Passkey Attack Bypasses Phishing-Resistant MFA and Impersonates Privileged Users
A newly disclosed “Pass-the-Passkey” attack family demonstrates how implementation weaknesses in WebAuthn can undermine passkey protections, even when private keys remain within hardware security keys or trusted device enclaves. SpecterOps researchers identified more than 20 attack techniques affecting Windows 11, Microsoft Entra ID, web browsers, password managers, and enterprise authentication workflows. The techniques do not […]
The post Pass-the-Passkey Attack Bypasses Phishing-Resistant MFA and Impersonates Privileged Users appeared first on Cyber Security News.