New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Summary
Researchers at Palo Alto Networks have uncovered new attack methods that can hijack accounts protected by Google's synced passkey implementation. These methods leverage malware to compromise user accounts secured by passkeys.
IFF Assessment
FOE
This article details new attack methods that can compromise security features, which is bad news for defenders.
Defender Context
This research highlights emerging threats to passkey security, a widely adopted authentication method. Defenders should be aware of potential malware-based attacks targeting passkeys and ensure user education on secure credential management practices.