Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Passkey Systems in New Attack Methods

Malware Exploits Passkey Systems in New Attack Methods

Posted on August 5, 2026 By CWS

Recent findings by Palo Alto Networks have highlighted sophisticated attack strategies targeting passwordless authentication systems. These methods demonstrate how malware can compromise accounts secured with passkeys, posing a significant threat to users and organizations.

Understanding Passkey Vulnerabilities

Passkeys are becoming more prevalent among major tech companies due to their enhanced security features against phishing attacks. However, the recently identified vulnerabilities, termed ‘Pass-ta-key’ by Palo Alto Networks, reveal potential risks associated with Google-synced passkeys. The researchers illustrated a scenario where an attacker could gain control of accounts without needing elevated permissions or user interaction.

In these attacks, malware already present on a Windows device with Chrome installed can analyze the browser’s local database. This allows the identification of online accounts protected by passkeys, including the usernames and encrypted credentials associated with them.

Detailed Attack Techniques

The attack involves extracting a device identity key stored by Chrome, either in memory or on disk. Through the use of Windows cryptographic APIs, the malware can generate a signature over a challenge from Google’s cloud authentication service, bypassing biometric prompts or the need for elevated privileges.

This process results in the cloud service validating the request as if it originated from a trusted device. Consequently, the attacker can send a valid authentication assertion to the targeted website, successfully completing the login process.

Advanced Variants and Mitigation Efforts

More advanced variations of this attack exist. The ‘Silver Pass-ta-key’ attack involves forcing Chrome into a re-registration process, allowing the malware to register its own verification key with the cloud authenticator during a brief window. This enables future authentication from a different machine.

The most severe form, ‘Golden Pass-ta-key’, involves extracting a master secret from Chrome’s memory, allowing the malware to decrypt all synchronized passkey private keys. This grants the attacker access to decrypt future passkeys as well.

Google has been informed of these vulnerabilities, and according to Palo Alto Networks, the tech giant has already implemented some mitigations to address the threats.

These revelations underscore the importance of continuous vigilance and updates in cybersecurity practices, especially as passwordless authentication becomes more widespread.

Security Week News Tags:Chrome, cyber attack, Cybersecurity, Google, Malware, Palo Alto Networks, Passkey, passwordless authentication, technology news, Windows

Post navigation

Previous Post: Kali365 Exploits Microsoft Login to Threaten US Firms
Next Post: Counterfeit Open VSX Extensions Compromise Developer Data

Related Posts

Google Says AI Agent Thwarted Exploitation of Critical Vulnerability  Google Says AI Agent Thwarted Exploitation of Critical Vulnerability  Security Week News
Klue Hack Affects Multiple Cybersecurity Firms Klue Hack Affects Multiple Cybersecurity Firms Security Week News
PyPI Warns Users of Fresh Phishing Campaign PyPI Warns Users of Fresh Phishing Campaign Security Week News
Windows Zero-Day Exploit Unveiled by Nightmare Eclipse Windows Zero-Day Exploit Unveiled by Nightmare Eclipse Security Week News
ToolShell Attacks Hit 400+ SharePoint Servers, US Government Victims Named ToolShell Attacks Hit 400+ SharePoint Servers, US Government Victims Named Security Week News
Nevada Ransomware Attack Started Months Before It Was Discovered, Per Report Nevada Ransomware Attack Started Months Before It Was Discovered, Per Report Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark