New Passkey Attacks Explained: What Security Researchers Found This August
Security Boulevard, Monday, August 24th, 2026
Black Hat researchers unveiled three passkey attack families that bypass authentication logging and sync.
Black Hat USA 2026 researchers disclosed three passkey attack families showing that authentication systems around passkeys, not the keys themselves, are the weak point.
SpecterOps' 'Pass-the-Passkey' exploited Windows 11 logging and Entra ID validation gaps to harvest and replay WebAuthn assertions and impersonate admins; Microsoft patched the logging flaw but Entra ID gaps remain open.
Palo Alto Networks' 'Golden Pass-ta-key' can recover the master secret protecting all of a user's synced Google Password Manager passkeys with no rotation option, while Dirk-jan Mollema showed malware can abuse Windows Hello for Business keys without fresh biometric verification-urgent given Microsoft's push to auto-enable passkeys for Entra ID users.