<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Passkeys on CuraSec</title><link>https://curasec.metacog.co.kr/tags/passkeys/</link><description>Recent content in Passkeys on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 13:03:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/passkeys/index.xml" rel="self" type="application/rss+xml"/><item><title>Vaulted Passkeys: Research Proposal for Device-Bound Credential Export</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-vaulted-passkeys-a-device-bound-proposal-for-authenticated-c/</link><pubDate>Mon, 17 Aug 2026 13:03:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-vaulted-passkeys-a-device-bound-proposal-for-authenticated-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel architecture for passkey export/import without plaintext key exposure — worth reading if you&amp;rsquo;re designing FIDO2 recovery flows, but this is a prototype proposal with no standard status yet and no action required on running systems.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Researchers Demonstrate Three Passkey Attack Classes That Bypass Phishing-Resistance</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you&amp;rsquo;re deploying or have deployed cloud-synced passkeys, evaluate migrating to hardware-bound (device-local) passkeys where possible; the research shows synced passkey material can be exfiltrated by malware and Windows-issued signed auth tokens can be replayed — audit your passkey configuration to prefer non-synced, phishing-resistant authenticators.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> These attacks require malware already present on the endpoint, making detection of credential-theft behaviors (auth token exfiltration, suspicious cloud-sync API calls) the relevant angle — no published IOCs or ATT&amp;amp;CK mappings yet, but worth revisiting passkey-related telemetry if new technique details emerge.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Passkey rollouts sold internally as phishing-proof may need a qualification: device-bound variants maintain that property but cloud-synced ones carry residual risk if endpoints are compromised — useful context for board decks or vendor questionnaire responses that reference passkey adoption.&lt;/li>
&lt;/ul></description></item><item><title>Pass-ta-key attacks enable passkey theft from compromised Windows via Google sync</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-new-pass-ta-key-attacks-let-malware-hijack-google-synced-pas/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-new-pass-ta-key-attacks-let-malware-hijack-google-synced-pas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Researchers demonstrate that Google Password Manager&amp;rsquo;s synced passkeys can be extracted once malware has endpoint access, undermining a key passkey security assumption. No patch available; factor this into threat models when recommending passkey adoption and ensure endpoint hardening is a prerequisite.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The attack chain requires malware already present on the host, so existing endpoint detection coverage is the primary defense; no IOCs or mapped TTPs are published yet to support a dedicated hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A novel attack class that weakens the &amp;lsquo;passkeys are phishing-resistant&amp;rsquo; narrative by showing synced credentials can be stolen post-compromise; useful context for briefings on authentication strategy but no immediate organizational action is warranted.&lt;/li>
&lt;/ul></description></item><item><title>Pass-ta-key: Malware Can Hijack Google Passkeys Without User Interaction</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-google-password-manager-attacks-could-let-malware-hijack-pas/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-google-password-manager-attacks-could-let-malware-hijack-pas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Unit 42&amp;rsquo;s three attack paths show that malware with ordinary user privileges can silently sign into passkey-protected accounts via Chrome&amp;rsquo;s Google Password Manager cloud authenticator, undermining the assumption that passkeys are malware-resistant. No patch is available; understand this changes the trust model for GPM-backed passkeys as a control and evaluate whether hardware-bound keys or platform authenticators offer stronger guarantees for high-value accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The three named techniques (Pass-ta-key variants) targeting Chrome&amp;rsquo;s credential store represent detectable post-exploitation behaviors; build detections around suspicious process access to Chrome&amp;rsquo;s local password/passkey storage and anomalous silent authentication events originating from endpoints, even without prior IOCs.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Research demonstrates that passkeys stored in Google Password Manager do not provide the malware-resistance often assumed in enterprise migration pitches; factor this into any planned passkey rollout strategy and update risk narratives shared with leadership or customers around phishing-resistant MFA claims.&lt;/li>
&lt;/ul></description></item><item><title>Passkey UV Flag Bypass Reduces Passwordless Auth to Single Factor</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-pass-the-passkey-a-novel-attack-surface-in-passwordless-auth/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-pass-the-passkey-a-novel-attack-surface-in-passwordless-auth/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit your WebAuthn/passkey relying party implementation to confirm the User Verified flag is enforced; if your app accepts assertions without UV=true, you&amp;rsquo;ve silently degraded MFA to single-factor auth.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No exploitation in the wild reported and no IOCs available; useful for understanding how passkey bypass could appear in authentication logs if UV flag checks are absent.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Entra ID makes passkeys the default auth method</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-entra-id-security-updates-passkeys-are-the-default/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-entra-id-security-updates-passkeys-are-the-default/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> This is a breaking change to default authentication behavior in Entra ID — audit your tenant&amp;rsquo;s authentication policy, test passkey rollout for user flows, and review the updated SMS/voice auth model before it affects production sign-ins.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Passkey adoption changes the phishing-resistant auth landscape and may affect credential-based attack detections; no immediate hunt or detection work required, but worth understanding how login telemetry shifts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A platform-level auth default change from a major identity provider warrants a quarter-horizon review of helpdesk readiness, user communication plans, and any compliance attestations tied to MFA method specifics.&lt;/li>
&lt;/ul></description></item></channel></rss>