Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    Unitree Robotics Is Going Public in Shanghai at a $9 Billion Valuation and It Makes the Robots You Have Already Seen Walking Around the Internet. Here Is Whether the IPO Price Reflects Reality or Hype

    August 25, 2026

    Apple Has Sent Mercenary Spyware Warning Notifications to iPhone Users Across 110 Countries. If You Got One You Need to Act Immediately. If You Did Not You Still Need to Read This

    August 25, 2026

    A New Study Found That 76% of AWS Accounts Are Publicly Exposed Compared to Just 8% on Google Cloud. The Gap Between the Two Platforms Is Bigger Than Most Security Teams Realise and the Consequences Are Already Showing Up in Breach Reports

    August 25, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Unitree Robotics Is Going Public in Shanghai at a $9 Billion Valuation and It Makes the Robots You Have Already Seen Walking Around the Internet. Here Is Whether the IPO Price Reflects Reality or Hype

      August 25, 2026

      Apple Has Sent Mercenary Spyware Warning Notifications to iPhone Users Across 110 Countries. If You Got One You Need to Act Immediately. If You Did Not You Still Need to Read This

      August 25, 2026

      A New Study Found That 76% of AWS Accounts Are Publicly Exposed Compared to Just 8% on Google Cloud. The Gap Between the Two Platforms Is Bigger Than Most Security Teams Realise and the Consequences Are Already Showing Up in Breach Reports

      August 25, 2026

      OpenAI Has Now Lost Two Senior Executives in the Same Week. The Timing Raises Questions the Company Has Not Yet Answered About What Is Happening at the Top.

      August 24, 2026

      Texas Welcomed Every AI Data Center That Wanted to Come. Now the State That Built Its Identity Around That Openness Is Pushing Back and the Reasons Go Deeper Than Power Grid Strain.

      August 24, 2026
    • Crypto

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026

      Coinbase Bets on Stablecoin and On-Chain Growth as Key Market Drivers in 2026 Strategy

      January 10, 2026
    • Gadgets & Smart Tech
      Featured

      Apple Just Delayed Development on Its Smart Glasses After Internal Privacy Reviews. The Delay Is the Clearest Sign Yet That Wearable AI Has a Trust Problem That Hardware Cannot Solve.

      By preciousAugust 4, 2026
      Recent

      Apple Just Delayed Development on Its Smart Glasses After Internal Privacy Reviews. The Delay Is the Clearest Sign Yet That Wearable AI Has a Trust Problem That Hardware Cannot Solve.

      August 4, 2026

      Microsoft Is Building Quantum-Resistant Security Before Quantum Computers Can Break the Encryption Protecting Everything. Here Is How Far Along That Work Actually Is

      July 21, 2026

      AI Has Spent Three Years Getting Smarter for People Who Can Already Afford It. Nokia Just Changed That and the Implications Go Further Than Anyone Is Crediting

      July 18, 2026
    • Cybersecurity & Online Safety

      A New Attack Family Called Pass-the-Passkey Just Bypassed the MFA That Was Supposed to Make Passwords Obsolete. Windows 11 and Microsoft Entra ID Are Both Affected and the Timing Could Not Be Worse

      August 25, 2026

      Microsoft’s August Patch Tuesday Fixed 398 Security Flaws Including a WinSock Zero-Day That Was Already Being Exploited Before Most People Knew It Existed. Here Is What to Prioritise

      August 24, 2026

      OpenAI’s New Cyber Model Found Two Real Chrome Zero-Days on Its Own. The Same Model Built to Defend Networks Just Proved It Can Also Break Into Them.

      August 23, 2026

      Hackers Leaked the Personal Contact Details of Over 100,000 UK Police Officers From a Legal Database Breach. The People Responsible for Public Safety Just Had Their Own Identities Exposed.

      August 23, 2026

      Autonomous AI Agents Ran a Four-Day Attack on Taiwan’s Government and Cracked 85 Accounts Without a Human Steering a Single Step. This Is No Longer a Theoretical Threat.

      August 21, 2026
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»A New Attack Family Called Pass-the-Passkey Just Bypassed the MFA That Was Supposed to Make Passwords Obsolete. Windows 11 and Microsoft Entra ID Are Both Affected and the Timing Could Not Be Worse
    Cybersecurity & Online Safety

    A New Attack Family Called Pass-the-Passkey Just Bypassed the MFA That Was Supposed to Make Passwords Obsolete. Windows 11 and Microsoft Entra ID Are Both Affected and the Timing Could Not Be Worse

    fariehanBy fariehanAugust 25, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Pass-the-Passkey attacks just found a crack in passwordless security. Researcher Michael Grafnetter revealed the attack family at Black Hat USA on August 5, 2026. As a result, Windows 11 and Microsoft Entra ID both face real exposure. 

    Developers built passkeys to replace passwords and stop phishing for good. Because of this, millions of companies trusted them without a second thought. However, new vulnerabilities are now testing that trust. Therefore, security teams are scrambling to check systems they once assumed are safe.

    The Pass-the-Passkey Attack That Shouldn’t Have Worked

    Researchers uncovered more than 20 ways to attack passkeys. Surprisingly, none of them crack passkey encryption itself. Instead, attackers target the systems working quietly behind the scenes, like logs and identity checks. 

    Three major flaws sit at the center of the discovery. Notably, two of them combine into the most dangerous attack of all. As a result, a hacker can pretend to be someone else entirely, with no stolen password required. Since passkeys guard powerful business accounts, this combination turns a technical bug into real financial risk.

    How a Logging Bug Became a Bypass

    The trouble started with Windows 11, which stored a copy of login proof inside its event log. This proof, called a WebAuthn assertion, was never meant to be reused. Nevertheless, Windows saved it anyway. Microsoft tracked this flaw as CVE-2026-34348. 

    Meanwhile, Microsoft Entra ID made things worse on its own end. Specifically, Entra ID accepted that saved proof for up to ten minutes after login. In addition, it skipped basic checks meant to block reused logins. 

    Because of these two failures together, stolen proof became a working key. Consequently, anyone able to read the log, even with limited access, could walk straight through.

    Why “Phishing-Resistant” Just Got Complicated

    Attackers use an old trick called pass-the-hash here. In both cases, they never touch your secret. Instead, they simply reuse proof that you already logged in successfully. Once a system trusts that reused proof, it opens without asking further questions. 

    Furthermore, low-level malware can grab that proof quietly, without triggering a single alarm. From there, a minor breach can escalate quickly and grow into full control of a cloud account. 

    Entra ID promises phishing-resistant login, yet this bypass slips right past that promise. As a result, it hits hardest at businesses running sensitive cloud systems.

    One Bug Down, One Still Open

    Microsoft closed the Windows logging flaw in its July 2026 update. Therefore, old login proof can no longer be replayed. Even so, one of the three original flaws remains unpatched today. 

    In the meantime, Microsoft is urging companies to limit access and adopt stronger login methods. Additionally, it recommends constant system monitoring while that gap stays open. Meanwhile, time pressure is building fast. Microsoft plans to make passkeys the default login starting September 1. 

    Before that day arrives, organizations should patch their systems and check who can read their logs. Ultimately, passkeys still beat passwords by a wide margin but this situation proves no login method is ever truly perfect.

    Black Hat USA 2026 CVE-2026-34348 FIDO2 encryption July 2026 security update MFA bypass attack Microsoft Entra ID Microsoft patch response Pass-the-Passkey passkey security flaw WebAuthn assertion vulnerability Windows 11 vulnerability zero-day vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    fariehan

    Related Posts

    Microsoft’s August Patch Tuesday Fixed 398 Security Flaws Including a WinSock Zero-Day That Was Already Being Exploited Before Most People Knew It Existed. Here Is What to Prioritise

    August 24, 2026

    OpenAI’s New Cyber Model Found Two Real Chrome Zero-Days on Its Own. The Same Model Built to Defend Networks Just Proved It Can Also Break Into Them.

    August 23, 2026

    Hackers Leaked the Personal Contact Details of Over 100,000 UK Police Officers From a Legal Database Breach. The People Responsible for Public Safety Just Had Their Own Identities Exposed.

    August 23, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Big Tech & Startups

    Unitree Robotics Is Going Public in Shanghai at a $9 Billion Valuation and It Makes the Robots You Have Already Seen Walking Around the Internet. Here Is Whether the IPO Price Reflects Reality or Hype

    By fariehanAugust 25, 2026

    Unitree Robotics has just gone public in Shanghai and audiences already recognize its robots. Viral…

    Apple Has Sent Mercenary Spyware Warning Notifications to iPhone Users Across 110 Countries. If You Got One You Need to Act Immediately. If You Did Not You Still Need to Read This

    August 25, 2026

    A New Study Found That 76% of AWS Accounts Are Publicly Exposed Compared to Just 8% on Google Cloud. The Gap Between the Two Platforms Is Bigger Than Most Security Teams Realise and the Consequences Are Already Showing Up in Breach Reports

    August 25, 2026

    A New Attack Family Called Pass-the-Passkey Just Bypassed the MFA That Was Supposed to Make Passwords Obsolete. Windows 11 and Microsoft Entra ID Are Both Affected and the Timing Could Not Be Worse

    August 25, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.