SpecterOps disclosed a "Pass-the-Passkey" attack family that can undermine passkey-based authentication in Windows 11 and Microsoft Entra ID without extracting private keys from hardware tokens or trusted enclaves. The most serious chain used Windows 11 event logging that recorded full WebAuthn assertion responses and paired it with Entra ID replay-validation weaknesses, allowing attackers to replay harvested assertions and gain access to privileged cloud accounts while still meeting phishing-resistant MFA checks. Microsoft addressed the Windows logging exposure as CVE-2026-34348, truncating logged signature fields to six bytes.
The research also described local attack paths that abuse legitimate WebAuthn APIs for prompt flooding, application identity spoofing, remote desktop pass-through, and Credential UI spoofing, enabling local passkey phishing and user-fatigue scenarios. Researchers released open-source tooling to help defenders test for assertion injection, event-log mining, and WebAuthn API hooking, and recommended patching Windows 11, enforcing server-side anti-replay protections, monitoring WebAuthn API activity, and requiring hardware-backed attestation for high-privilege Entra ID accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft addressed the Windows 11 issue tracked as CVE-2026-34348 in its July 14, 2026 security release. The fix truncated logged WebAuthn signature fields to six bytes to prevent replay of harvested assertions from Event Logs.
A Security Friends research post documented a technique for evading Microsoft Entra ID Conditional Access policies via cross-tenant Resource Owner Password Credentials flows. The reference establishes public disclosure of the research on that date.
SpecterOps disclosed a family of more than 20 attack techniques exploiting weaknesses in WebAuthn implementations across Windows 11, Microsoft Entra ID, browsers, password managers, and enterprise authentication workflows. The research highlighted replay attacks enabled by Windows 11 logging full WebAuthn assertions and Entra ID failing to enforce key anti-replay checks, and it also released open-source defensive testing tools.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.fndsec.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.