ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Passkey authentication can be subverted to steal synced private keys

Source headline: New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Multiple studies showed ways to defeat passkey protections without breaking the underlying cryptography. The techniques focus on reusing signed authentication artifacts exposed by Windows systems and on abusing cloud-synced passkey flows. In some cases, malware already present on the victim’s machine was able to leverage the synced passkey setup. This could enable account takeover even when users avoid reusable passwords and phishing-resistant MFA is enabled. Users should review passkey usage, ensure devices are clean of malware, and tighten authentication and recovery settings with their identity provider.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#account-takeover #mfa #windows #passkeys #cloud-sync #phishing-resistant
Original reporting The Hacker News New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Open original source