<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication on CuraSec</title><link>https://curasec.metacog.co.kr/tags/authentication/</link><description>Recent content in Authentication on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 11:54:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/authentication/index.xml" rel="self" type="application/rss+xml"/><item><title>Researchers Demonstrate Three Passkey Attack Classes That Bypass Phishing-Resistance</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you&amp;rsquo;re deploying or have deployed cloud-synced passkeys, evaluate migrating to hardware-bound (device-local) passkeys where possible; the research shows synced passkey material can be exfiltrated by malware and Windows-issued signed auth tokens can be replayed — audit your passkey configuration to prefer non-synced, phishing-resistant authenticators.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> These attacks require malware already present on the endpoint, making detection of credential-theft behaviors (auth token exfiltration, suspicious cloud-sync API calls) the relevant angle — no published IOCs or ATT&amp;amp;CK mappings yet, but worth revisiting passkey-related telemetry if new technique details emerge.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Passkey rollouts sold internally as phishing-proof may need a qualification: device-bound variants maintain that property but cloud-synced ones carry residual risk if endpoints are compromised — useful context for board decks or vendor questionnaire responses that reference passkey adoption.&lt;/li>
&lt;/ul></description></item><item><title>macOS sudo unlocked via local face recognition (GitHub: macos-faceid)</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-lorenzo-coslado-macos-faceid-52/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-lorenzo-coslado-macos-faceid-52/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A PAM-level biometric hook for sudo is worth evaluating before someone on your team installs it on a managed Mac; understand what attack surface a local face-recognition bypass introduces before adopting or banning it.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Passkey UV Flag Bypass Reduces Passwordless Auth to Single Factor</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-pass-the-passkey-a-novel-attack-surface-in-passwordless-auth/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-pass-the-passkey-a-novel-attack-surface-in-passwordless-auth/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit your WebAuthn/passkey relying party implementation to confirm the User Verified flag is enforced; if your app accepts assertions without UV=true, you&amp;rsquo;ve silently degraded MFA to single-factor auth.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No exploitation in the wild reported and no IOCs available; useful for understanding how passkey bypass could appear in authentication logs if UV flag checks are absent.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>