New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Summary

Researchers at Palo Alto Networks have uncovered new attack methods that can hijack accounts protected by Google's synced passkey implementation. These methods leverage malware to compromise user accounts secured by passkeys.

IFF Assessment

FOE

This article details new attack methods that can compromise security features, which is bad news for defenders.

Defender Context

This research highlights emerging threats to passkey security, a widely adopted authentication method. Defenders should be aware of potential malware-based attacks targeting passkeys and ensure user education on secure credential management practices.

Read Full Story →