New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three research efforts (SpecterOps, Palo Alto Networks Unit 42, and a Windows Hello for Business chain) demonstrated that passkey protections can be defeated without breaking the underlying cryptography โ by reusing signed authentication material Windows had exposed, abusing cloud-synced passkey systems from malware already on a victim machine, and using a Windows Hello for Business key from a compromised user session without a fresh PIN or biometric check.
Summary
| Field | Detail |
|---|---|
| Researchers | SpecterOps, Palo Alto Networks Unit 42, Windows Hello for Business chain |
| Target | Passkey protections (synced private keys, phishing-resistant MFA) |
| Mechanism | Reuse of exposed signed authentication material; abuse of cloud-synced passkey systems from on-device malware; WHfB key use without fresh PIN/biometric check |
| Notable result | SpecterOps: Windows/Entra ID chain can impersonate privileged users while satisfying phishing-resistant MFA |
| Confidence | Confirmed (published technical research, not yet observed in the wild) |
| Date | 2026-08-10 |
Key Details
- SpecterOps showed a Windows/Entra ID chain that can impersonate privileged users while satisfying phishing-resistant MFA.
- One attack path reuses signed authentication material Windows had exposed, without breaking the underlying cryptography.
- Another path abuses cloud-synced passkey systems from malware already running on a victim machine.
- A Windows Hello for Business key can be used from a compromised user session without a fresh PIN or biometric check.
Significance
The research demonstrates that phishing-resistant MFA mechanisms are not immune to compromise โ the attacks bypass the protections without defeating the cryptography itself, typically requiring prior device compromise. Reinforces the week's priority ordering: patch velocity on internet-exposed surfaces and human review of AI-driven remediation alongside phishing-resistant MFA deployment.
Source
- The Hacker News โ 2026-08-10
Sources: raw/digests/Cyber-Digest-2026-08-11