Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, technique, passkey, mfa, phishing-resistant-mfa, mfa-bypass, research, entraid, sector-technology] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Three research efforts (SpecterOps, Palo Alto Networks Unit 42, and a Windows Hello for Business chain) demonstrated that passkey protections can be defeated without breaking the underlying cryptography โ€” by reusing signed authentication material Windows had exposed, abusing cloud-synced passkey systems from malware already on a victim machine, and using a Windows Hello for Business key from a compromised user session without a fresh PIN or biometric check.

Summary

Field Detail
Researchers SpecterOps, Palo Alto Networks Unit 42, Windows Hello for Business chain
Target Passkey protections (synced private keys, phishing-resistant MFA)
Mechanism Reuse of exposed signed authentication material; abuse of cloud-synced passkey systems from on-device malware; WHfB key use without fresh PIN/biometric check
Notable result SpecterOps: Windows/Entra ID chain can impersonate privileged users while satisfying phishing-resistant MFA
Confidence Confirmed (published technical research, not yet observed in the wild)
Date 2026-08-10

Key Details

  • SpecterOps showed a Windows/Entra ID chain that can impersonate privileged users while satisfying phishing-resistant MFA.
  • One attack path reuses signed authentication material Windows had exposed, without breaking the underlying cryptography.
  • Another path abuses cloud-synced passkey systems from malware already running on a victim machine.
  • A Windows Hello for Business key can be used from a compromised user session without a fresh PIN or biometric check.

Significance

The research demonstrates that phishing-resistant MFA mechanisms are not immune to compromise โ€” the attacks bypass the protections without defeating the cryptography itself, typically requiring prior device compromise. Reinforces the week's priority ordering: patch velocity on internet-exposed surfaces and human review of AI-driven remediation alongside phishing-resistant MFA deployment.

Source

Sources: raw/digests/Cyber-Digest-2026-08-11