THE article discusses newly discovered passkey attacks that can either recover synced private keys or bypass phishing-resistant multi-factor authentication (MFA). The attacks exploit vulnerabilities in how passkeys are stored and used, raising concerns about the effectiveness of current security measures. This highlights the need for enhanced strategies and solutions to safeguard against these emerging threats in identity security.
Passkey Flaws Allow Attackers to Steal Synced Keys and Bypass MFA
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT