Security News

Cybersecurity news aggregator

HIGH Vulnerabilities Dark Reading

Flaws in Passkey Implementation Show Old Attacks Still Work

A "Pass-the-Passkey" replay attack chain exploiting flaws in Microsoft's passkey implementation (CVE-2026-34348, CVSS 6.5) can allow attackers to impersonate privileged cloud identities and bypass phishing-resistant MFA. Affected versions include Microsoft Windows 10 1809 prior to 10.0.17763.9020 and Windows 10 21H2 prior to 10.0.19044.7548, among others listed in the NVD data. The vulnerabilities have been patched in the specified fixed versions.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources IDENTITY & ACCESS MANAGEMENT SECURITY ENDPOINT SECURITY СLOUD SECURITY VULNERABILITIES & THREATS News, news analysis, and commentary on the latest trends in cybersecurity technology. Flaws in Passkey Implementation Show Old Attacks Still Work Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users. Arielle Waldman,Features Writer,Dark Reading July 22, 2026 3 Min Read SOURCE: ATNOYDUR VIA GETTY IMAGES Attackers can exploit flaws in Microsoft's passkey systems in ways surprisingly similar to old password attacks, but that doesn't mean it's time to give up on passkeys. There's been a lot of attention on passkeys in recent years. They're considered phishing-resistant, and their use of private keys means they are largely unaffected by data breaches where identity information and credentials are stolen. They also require zero memorization compared to traditional passwords because users embed authentication directly into the device by enabling biometrics or PINs. Even so, widespread adoption has been gradual. That may change as Microsoft has announced that starting Sept. 1, passkeys will become the default authentication method for Microsoft Entra ID sign-in, the tech giant's cloud-based identity and access management service. With passkeys steadily becoming the norm, Michael Grafnetter, principal security researcher at SpecterOps, dug deeper into the security and risks of the passwordless alternative. That research, which will be presented next month at Black Hat USA conference in Las Vegas, uncovered three nearly exploitable zero-day vulnerabilities in Windows 11 and Microsoft Entra ID. Two of the vulnerabilities Grafnetter found formed a replay chain that could eventually allow attackers to impersonate privileged cloud identities while bypassing phishing-resistant multifactor authentication (MFA). Related:Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Grafnetter calls the chain "Pass-the-Passkey" because it mirrors similar Windows hacking techniques, such as pass-the-hash and NTLM Relay, where attackers steal and reuse authentication credentials without needing the actual password. "Passkeys are still a major improvement over passwords, but they are not magic," Grafnetter tells Dark Reading. "Our research shows that if surrounding implementation is flawed, attackers can still reintroduce replay, relay, and phishing-like attack paths even when the underlying WebAuthn cryptography is sound." 'One Uncomfortable Lesson' WebAuthn, developed as a joint initiative by the World Wide Web Consortium (W3C) and the FIDO (Fast Identity Online) Alliance, is the underlying technology that drives passkeys. It plays a crucial role by issuing specialized digital credentials that verify a user's identity when logging into secure systems. However, SpecterOps research found that Windows 11 was essentially writing a complete copy of the digital key to the event log. On top of that, Entra ID failed to properly prevent those assertions from being reused, adds Grafnetter, noting that organizations using Windows Hello or FIDO2 security keys such as Yubikeys with Entra ID should pay particular attention to these flaws. Related:Oracle Red Bull Racing Team Revs Up Automation to Boost Security An attacker could exploit these flaws to impersonate privileged cloud users and bypass phishing-resistant MFA requirements, he warns. The main risk is not the standard itself, but incomplete or incorrect implementations, warns Grafnetter. He urges developers to rely on well-tested WebAuthn frameworks rather than build their own, since passkey validation involves non-trivial cryptography and several important checks. "One uncomfortable lesson from our research is that even Microsoft, one of the co-authors of the standard, missed some of the WebAuthn assertion validation steps required by the specification," he reveals. The researchers disclosed the findings to Microsoft, which "silently deployed a mitigation in their cloud services." Grafnetter only discovered the fix while recording demonstrations for his Black Hat presentation. The main Windows passkey vulnerability was assigned CVE-2026-34348, "a protection mechanism failure in Windows Event Logging Service that could allow an attacker to disclose information over a network". It was patched on July 14, which Grafnetter notes was the last Patch Tuesday before the Black Hat conference. Related:Microsoft Proposes Better Identity, Guardrails for AI Agents Don't Write Off Passkeys Yet Not only did the research reveal holes in Microsoft's passkey systems, but it also highlighted a broader industry lesson: Passkeys shift the attackers' focus rather than eliminate it, says Grafnetter. Passkeys provide access, and that's exactly what threat actors target. For privileged users in particular, he recommends that organizations should prefer device-bound passkeys, enforce attestation, and avoid relying on phishing-resistant MFA as their only layer of protection. Passkey cryptography may be strong, but endpoint security and server-side validation still matter a great deal, he stresses. Organizations should patch Windows 11, restrict code execution, use privileged-access workstations, and limit remote log access to address the flaws identified in these findings. Even so, he remains "optimistic about the security of passkeys." "The attack paths we describe remain much more complex than those in traditional password attacks, so we continue to recommend adopting passkeys," he says. Read more about: Black Hat News About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything More Webinars You May Also Like IDENTITY & ACCESS MANAGEMENT SECURITY Oracle Red Bull Racing Team Revs Up Automation to Boost Security by Arielle Waldman APR 30, 2026 IDENTITY & ACCESS MANAGEMENT SECURITY Orgs Move to SSO, Passkeys to Solve Bad Password Habits by Nate Nelson NOV 13, 2025 IDENTITY & ACCESS MANAGEMENT SECURITY NIST Digital Identity Guidelines Evolve With Threat Landscape by Arielle Waldman AUG 14, 2025 IDENTITY & ACCESS MANAGEMENT SECURITY Palo Alto Networks Grabs IAM Provider CyberArk for $25B by Rob Wright JUL 30, 2025 Latest Articles in DR Technology CYBERSECURITY OPERATIONS Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push JUL 20, 2026 СLOUD SECURITY Google Bets 'Agentic Defense' Strategy Can Outpace Attackers JUL 17, 2026 CYBERSECURITY OPERATIONS Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal JUL 15, 2026 CYBERATTACKS & DATA BREACHES Turning the Tables on Email Scammers With 'ScamBuster' JUL 13, 2026 Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article