Signal

New malware attacks exploit passkey onboarding and recovery flaws to hijack accounts

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-08-05 11:11 UTCUpdated 2026-08-05 23:51 UTC
rss
cveexploitsmalwarethreat_actorsincident_responsesecurity_tooling
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Google’s synchronized passkeys can be stolen in 'Pass‑ta‑key' attacks
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-08-05 11:11 UTC
Overview

Recent research by Palo Alto Networks Unit 42 reveals that malware can bypass passkey protections by exploiting weaknesses in onboarding, recovery, and device trust workflows rather than breaking passkey cryptography itself.

Entities
GooglePalo Alto NetworksMicrosoftPass-ta-keyKali365Justin Greis
Score total
1.41
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • Palo Alto Networks recently disclosed new attack methods against Google’s synchronized passkeys.
  • Google reports 800 million accounts using passkeys, increasing the potential attack surface.
  • Kali365 phishing attacks targeting Microsoft authentication highlight ongoing enterprise risks.
Why it matters
  • Passkeys are increasingly adopted as a secure password replacement, but procedural flaws expose users to account takeover.
  • Malware exploiting onboarding and recovery workflows can bypass strong cryptographic protections, undermining passkey security.
  • Enterprise authentication systems remain vulnerable to phishing kits like Kali365, risking data exposure and fraud.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • Malware can hijack passkey-protected accounts by exploiting onboarding, recovery, and device trust workflow weaknesses rather than breaking passkey cryptography.
  • Kali365 phishing kit weaponizes Microsoft authentication by tricking victims into approving attacker-controlled device codes, enabling persistent access to corporate resources.
How sources frame it
  • Justin Greis, CEO Of Acceligence: neutral
This briefing highlights emerging malware techniques that bypass passkey protections by targeting procedural weaknesses, emphasizing the need for improved onboarding and recovery security.
All evidence
All evidence
Report: Passkey security issues could allow account takeover
CSO Online · csoonline.com · 2026-08-05 23:51 UTC
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
SecurityWeek · securityweek.com · 2026-08-05 12:48 UTC
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
thehackernews · thehackernews.com · 2026-08-05 11:43 UTC
Google’s synchronized passkeys can be stolen in 'Pass‑ta‑key' attacks
Malwarebytes Threat Analysis · malwarebytes.com · 2026-08-05 11:11 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • CSO Online (1)
  • SecurityWeek (1)
  • thehackernews (1)
  • Malwarebytes Threat Analysis (1)
Top origin domains (this list)
  • csoonline.com (1)
  • securityweek.com (1)
  • thehackernews.com (1)
  • malwarebytes.com (1)