← Back to feed
PhishingEmerging1 sourceAug 11, 2026 · 06:51via CyberPress

Pass-the-Passkey Attack Bypasses Phishing-Resistant MFA and Impersonates Privileged Users

Brief

A newly disclosed “Pass-the-Passkey” attack family demonstrates how implementation weaknesses in WebAuthn can undermine passkey protections, even when private keys remain within hardware security keys or trusted device enclaves.

SpecterOps researchers identified more than 20 attack techniques affecting Windows 11, Microsoft Entra ID, web browsers, password managers, and enterprise authentication workflows.

The techniques do not break FIDO2 cryptography or extract private keys. Instead, they exploit the ecosystem around passkeys, including endpoint logging, server-side assertion validation, authentication prompts, and application interfaces.

Pass-the-Passkey Attack

The most serious attack chain combines a Windows event logging flaw with insufficient WebAuthn validation in Microsoft Entra ID.

Read more on CyberPress