< ciso
brief />
Tag Banner

All news with #passkeys tag

30 articles

UK police urge public to adopt passkeys now

🔒 The UK’s Report Fraud service has launched a public campaign urging internet users to adopt passkeys after reporting a sharp rise in funds stolen via email and social media account takeovers. Losses from such cybercrime rose to £6.3m in 2025/6, up from £1.2m the prior year, while reports of account takeover increased by 34%. Officials and experts say passkeys — which use device PINs or biometrics and keep private keys on the device — are more resilient to phishing and credential theft than passwords.
read more →

Microsoft urges Entra ID migration to passkeys

🔐 Microsoft reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the retirement of SMS first-factor sign-ins in February 2027. Admins can also use QR code authentication, FIDO2 security keys, or other Entra ID-supported methods. The retirement affects workforce tenant authentication and not Azure AD B2C or Entra External ID scenarios. Microsoft provided guidance and tools, including a PowerShell scanner, to help identify impacted users.
read more →

Strengthen Fundamentals to Enable Next‑Gen Security

🔒 Effective cyber defense hinges on strong fundamentals rather than constantly chasing the latest tools. The author, a CISO with large-enterprise experience, argues that visibility, identity management, risk‑based prioritization, resilience and a common security language are core. Embracing AI and other innovations is valuable but only when built on these basics. Organizations should inventory assets, scale identity controls like MFA and passkeys, focus on crown-jewel protections, rehearse recovery plans, and translate technical risk into business terms.
read more →

Threat Actors Use Passkey Phishing to Breach Cloud

🛡️ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more →

Passkey-Themed Scams Hijacking Microsoft 365 Accounts

🔒 Microsoft Security Research has tracked a campaign since May where attackers pose as IT helpdesk staff to trick employees into updating or enrolling a passkey. Victims are redirected to AiTM phishing pages or legitimate Microsoft device-code flows, enabling attackers to capture credentials and session tokens or authorize attacker-controlled clients. Compromised identities allowed adversaries to register their own authentication methods, use Microsoft Graph to map tenants, and exfiltrate files and email from SharePoint, OneDrive, and Exchange.
read more →

Microsoft shifts Entra ID to passkeys as default

🔐 As of Sept. 1, Microsoft made passkeys the default authentication method for Entra ID, and plans to retire Microsoft-provided SMS and voice authentication by Feb. 1, 2027. The change accelerates enterprise adoption of passwordless methods but leaves many organizations operating in a hybrid environment due to legacy applications, recovery and governance challenges. Experts praise the phishing resistance of passkeys while warning about device lifecycle, ecosystem lock-in, fragmented cross-platform support, and account recovery complexities that can keep passwords in place for specialized or older systems.
read more →

WhatsApp adds multiple passkeys and stronger 2FA

🔐 Meta announced new WhatsApp security features, including support for multiple passkeys per account to enable phishing-resistant sign-ins across iOS and Android. The company reported over 1 billion users now sign in with passkeys and added a full password option for two-step verification, replacing the previous six-digit PIN. Android users will also receive added call context for unknown callers, such as origin and shared groups. Settings for passkey management are available under Settings > Account > Passkeys.
read more →

WhatsApp strengthens account security with passkeys

🔐 WhatsApp is rolling out several account security improvements, including support for multiple passkeys and an upgraded two-step verification option. Users can now create separate passkeys per platform (Android and iOS) and replace the previous six-digit PIN with a longer alphanumeric password. The update also adds more context on call screens for unknown callers to help users spot potential scams.
read more →

Research reveals practical weaknesses in passkey deployments

🔐 Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more →

Report: Passkey weaknesses expose account takeover risks

🔒 A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

Passkeys at Risk: Chrome Password Manager Attacks

🔒 Unit 42 describes three post-compromise attacks against Chrome's Google Password Manager cloud authenticator—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that let malware on Windows obtain valid authentication assertions or extract the master secret without user interaction. The techniques exploit how Chrome stores and reloads TPM-wrapped keys, allows deferred user-verification key creation during re-enrollment, and exposes the 32-byte Security Domain Secret (SDS) in process memory. The research is limited to Windows with TPM and starts from a compromised endpoint; it does not claim cryptographic failure and has no CVEs listed as of August 3, 2026.
read more →

Risks and Attacks Targeting Passkey Authentication

🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
read more →

Tycoon2FA takedown reshapes phishing landscape

🔎 Microsoft reports that disruption of the Tycoon2FA phishing-as-a-service platform drove a sharp decline in traditional phishing techniques, with platform-linked volume falling 92% from pre-takedown averages. The takedown reduced QR code and CAPTCHA-gated phishing and forced attackers to adapt, shifting to channels like Microsoft Teams and automated BEC campaigns. Microsoft recommends stronger email filtering and phishing-resistant authentication such as passkeys, FIDO keys, and multifactor protections to mitigate evolving threats.
read more →

Microsoft Entra ID makes passkeys default by 2026

🔐 Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, automatically enabling them for users currently relying on SMS and voice MFA. Those phone-based methods will be retired as native Entra capabilities on February 1, 2027, though organizations can use third-party telecom providers if needed. Users already on phishing-resistant methods like Windows Hello for Business, FIDO2 keys, or smart cards can continue using them without change.
read more →

Microsoft makes passkeys default for Entra ID

🔒 Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more →

Vishing campaign abuses Entra passkey enrollment

🔔 A threat actor is using voice-based fake security calls to trick Microsoft 365 users into enrolling a malicious Entra passkey. The attacker directs victims to realistic phishing pages that mimic the Microsoft enrollment flow and uses an operator-controlled PHP kit to capture credentials and MFA responses in real time. Okta attributes the campaign to O-UNC-066, linked to the extortion group Pink, which targets multiple industries and quickly exfiltrates data after account takeover.
read more →

Why attackers target your email inbox aggressively

📧 Email accounts act as hubs for identity verification, password resets and long-term records, making them prime targets for cybercriminals. Attackers use phishing, account takeover, forwarding rules and abused tokens to maintain access, intercept codes and harvest sensitive information. Corporate inbox breaches can lead to data theft, ransomware or expensive fraud, while sophisticated tools like GenAI increase phishing success rates. Regularly review security settings, use MFA or passkeys, and remain vigilant to reduce risk.
read more →

World Passkey Day: Microsoft Pushes Passwordless Future

🔐 Microsoft marks World Passkey Day by outlining steps to accelerate passkey adoption and reduce reliance on passwords and phishable methods. The company highlights work with the FIDO Alliance, expanded Microsoft Entra passkey support, Windows Hello device‑bound keys, and syncing through Microsoft Password Manager. It also strengthens account recovery with verified ID and biometric checks and plans to remove security questions in Entra ID by January 2027. Organizations are urged to enable passkeys and apply policies across sign‑in and recovery.
read more →