CyberSecurity News
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
AI summary
Researchers have discovered methods to bypass passkey protections, which are intended to replace traditional passwords and provide resistance to phishing attacks. These methods do not involve breaking the underlying cryptography, but rather exploit other vulnerabilities. One approach reuses signed authentication material that has been exposed by Windows. Another method involves abusing a cloud-synced passkey system using malware that is already present on the victim's machine. A third technique was also identified, although details of this specific attack are not provided. These findings suggest that passkey protections may be vulnerable to certain types of attacks.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

