CyberNews
← Back to dashboard
NEWS The Hacker News

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA - The Hacker News

Aug 10, 2026, 12:25 PM · by The Hacker News

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.

Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a Windows Hello for Business key from a compromised user session without a fresh PIN or biometric check. None cracked the math.

The impact is not the same in all three cases.

The fixes and mitigations differ too. Microsoft's Windows logging vulnerability, CVE-2026-34348, has a vendor CVSS score of 6.5 and a Microsoft security update. Microsoft told The Hacker News that it has also applied mitigations for the reported issue involving passkey relay assertions.

Source: The Hacker News