Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT NewsSecurity Boulevard

New Passkey Attacks Explained: What Security Researchers Found This August

Security Boulevard, Monday, August 24th, 2026

Black Hat researchers unveiled three passkey attack families that bypass authentication logging and sync.

Black Hat USA 2026 researchers disclosed three passkey attack families showing that authentication systems around passkeys, not the keys themselves, are the weak point.

SpecterOps' 'Pass-the-Passkey' exploited Windows 11 logging and Entra ID validation gaps to harvest and replay WebAuthn assertions and impersonate admins; Microsoft patched the logging flaw but Entra ID gaps remain open.

Palo Alto Networks' 'Golden Pass-ta-key' can recover the master secret protecting all of a user's synced Google Password Manager passkeys with no rotation option, while Dirk-jan Mollema showed malware can abuse Windows Hello for Business keys without fresh biometric verification-urgent given Microsoft's push to auto-enable passkeys for Entra ID users.

more →  ·  More from Security Boulevard →