
Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access
A newly disclosed technique shows how attackers with access to an active Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys without knowing the victim’s PIN or triggering biometric verification. The method can enable cloud authentication, Microsoft Entra ID token acquisition, device registration, and potentially persistent account access. Mollema’s research demonstrates that […]
The post Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access appeared first on Cyber Security News.