Enterprise passkey security under threat from malware

Summary

A Palo Alto Networks Unit 42 report details how attackers can bypass passkey security through malware on compromised endpoints, exploiting onboarding, recovery, and trust workflows. These attacks, collectively named Pass-ta-key, do not break the underlying cryptography but rather leverage weaknesses in the surrounding processes. The exploits can lead to account takeover, bypass user verification, and allow for the extraction of synced passkeys.

IFF Assessment

FOE

The article discusses new methods for attackers to compromise passkey-protected accounts, representing a significant threat to enterprise security.

Defender Context

This research highlights critical vulnerabilities in the implementation and management of passkey ecosystems, rather than the passkey technology itself. Defenders need to focus on securing endpoints against malware, scrutinizing onboarding and recovery processes, and ensuring robust validation of trust signals to prevent these types of attacks.

Read Full Story →