Enterprise passkey security under threat from malware
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion. They also pointed out that the issues are not strictly caused by holes in passkeys so much as by…
Enterprise passkey security is facing new threats from malware, according to a report by Palo Alto Networks Unit 42. The researchers found ways attackers can exploit passkey protections after successfully infiltrating an environment. These attacks, collectively dubbed Pass-ta-key, include taking over Google-synced accounts without privilege escalation, tricking Google Cloud Authenticator into believing a user has unlocked the device with biometrics, and extracting all synced passkeys for sale on the black market.
Palo Alto analysts emphasized that the flaws are not inherent to passkeys, but rather stem from weaknesses in the procedures surrounding them, such as onboarding, recovery mechanisms, and trust signals. The report highlights that the real risk lies in the lack of attention paid to these mechanisms and the uneven implementation across enterprises.
CISOs should focus on user verification, validate user-verified flags, and require strong authentication for privileged access.
Written by urgent.news from Computerworld's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.