Passkey authentication can be subverted to steal synced private keys
Source headline: New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Intelligence Summary
Multiple studies showed ways to defeat passkey protections without breaking the underlying cryptography. The techniques focus on reusing signed authentication artifacts exposed by Windows systems and on abusing cloud-synced passkey flows. In some cases, malware already present on the victim’s machine was able to leverage the synced passkey setup. This could enable account takeover even when users avoid reusable passwords and phishing-resistant MFA is enabled. Users should review passkey usage, ensure devices are clean of malware, and tighten authentication and recovery settings with their identity provider.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.