Flaws in Passkey Implementation Show Old Attacks Still Work
As Microsoft gears up to make passkeys the default authentication method for its cloud-based identity and access management service, a closer look at their implementation has revealed some unsettling vulnerabilities. Researchers from SpecterOps have found three nearly exploitable zero-day flaws in Windows 11 and Microsoft Entra ID that could allow attackers to impersonate privileged users, … Read more