| |
Researchers have identified new attack vectors against passwordless authentication systems, particularly Google's synced passkey ecosystem, where malware on compromised endpoints can exploit onboarding and recovery workflows to take over accounts, extract private keys, and authenticate without user interaction. While passkeys were designed to eliminate traditional password-based attacks, this research demonstrates that attackers are evolving their tactics to target the new authentication infrastructure as passkey adoption scales globally. Palo Alto Networks has released security tools to defend against these newly disclosed attack vectors.
Read Full Article →
← More Tech news