A new attack reveals significant security vulnerabilities in passkey implementations, particularly exposing how Windows-based passkey apps handle authentication differently than other operating systems.
The Pass-ta-key attack demonstrates critical inconsistencies in how passkey applications manage security across platforms. Windows implementations of passkey technology treat authentication differently than macOS and Linux variants, creating potential security gaps that attackers can exploit.
Passkeys, designed as a passwordless authentication method, have been promoted as a security upgrade. However, the research reveals these systems may not provide the uniform protection users expect. The vulnerability stems from platform-specific implementation differences rather than fundamental flaws in the passkey protocol itself.
Security researchers found that Windows passkey apps often fail to enforce the same verification standards applied on other platforms. This inconsistency allows attackers to bypass intended security measures under specific conditions.
The findings raise questions about passkey adoption across enterprise and consumer environments. Industry stakeholders including tech companies supporting passkey standards now face pressure to standardize implementation practices across all operating systems. Organizations considering passkey deployment should review their specific platform implementations before widespread rollout.
Cisco has disclosed two high-severity vulnerabilities in ClamAV that attackers can exploit to crash the scanning process. Public exploits are already available.
A New Bedford police officer faces allegations of using Flock automated license plate reader cameras to track an ex-romantic partner. The incident raises questions about surveillance tool oversight within law enforcement.
The FBI's Atlanta office is investigating a suspected fake Wi-Fi hotspot attack targeting a Delta flight, with DEF CON attendees under suspicion. No arrests have been made.
Google Chrome is implementing device-bound session credentials, a security feature designed to block account takeovers by tying login sessions to specific devices. The technology addresses a growing threat where attackers steal credentials to gain unauthorized access.