:

MALWARE CAN HIJACK GOOGLE'S SYNCED PASSKEYS

SECURITY DESK1 MIN READ
TUE, AUG 4, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security researchers discovered three attacks allowing malware on compromised Windows devices to abuse Google Password Manager's synced passkeys, potentially taking over accounts and extracting private keys.

The vulnerabilities affect Google Password Manager's passkey synchronization feature on Windows. Attackers exploiting already-installed malware can bypass user verification, hijack passkeys stored in the cloud service, and extract the private keys used to authenticate accounts. The three discovered attack vectors target different aspects of how Google syncs and manages passkeys locally. Once compromised, attackers gain access to passkeys without requiring additional user interaction or credentials. Passkeys represent the next generation of authentication, designed to replace passwords with cryptographic key pairs. However, cloud synchronization of these keys—while improving user convenience—introduces centralized risk if the local device is compromised. Google Password Manager users on Windows should ensure their devices have active malware protection and keep systems updated. The findings highlight the critical need for endpoint security when using cloud-synced authentication methods.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

JUST NOWSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

2H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

7H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

10H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.