Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Windows Hello Keys for Entra ID Access

Malware Exploits Windows Hello Keys for Entra ID Access

Posted on August 7, 2026 By CWS

A recent finding by researcher Dirk-jan Mollema has unveiled a potential security flaw in Windows systems, where malware, once active in a signed-in session, can exploit Windows Hello for Business keys to gain access to Microsoft Entra ID. This vulnerability allows attackers to achieve persistent access without needing administrator privileges, highlighting a significant concern in endpoint security.

Understanding the Exploit

The vulnerability, demonstrated by Mollema, involves malware using the victim’s Windows Hello for Business key to authenticate with Microsoft Entra ID. This method does not require extracting private keys, recovering PINs, or triggering biometric prompts. Instead, the system’s ticketing behavior maintains private-key operations accessible during interactive sessions.

This approach allows malicious code to request Windows to sign authentication data, effectively enabling unauthorized access. The attack requires the malware to execute within an active session, leveraging how Windows Hello for Business operates. Importantly, no current reports of active exploitation or specific victim cases have been documented.

Implications for Cloud Access and Device Registration

By exploiting this vulnerability, attackers can secure prolonged cloud access, register new devices under their control, and even obtain a Primary Refresh Token (PRT). This token can be continuously renewed, granting ongoing cloud service access for up to 90 days, provided the user remains active.

Mollema further demonstrated that the technique bypasses prior requirements by treating Windows Hello for Business keys as FIDO2 passkeys through WebAuthn. This new method allows an attacker to generate the necessary signed assertions on a compromised endpoint, facilitating unauthorized access to Microsoft cloud services.

Security Measures and Recommendations

To mitigate this potential threat, Mollema advises monitoring for unexpected device registrations and scrutinizing Windows Hello for Business sign-ins that lack a device ID. Such patterns could indicate unauthorized access attempts. Despite the absence of a CVE or official advisory from Microsoft, staying vigilant and employing robust security policies is crucial.

Microsoft’s documentation acknowledges the ticketing behavior, but the lack of immediate corrective action underscores the need for organizations to implement supplementary security measures. Detection of suspicious activity and adherence to strict Conditional Access policies can serve as effective deterrents against such exploits.

The research, including PowerShell proof-of-concept scripts, is available for cybersecurity professionals aiming to understand and counteract this vulnerability. It is essential to address these concerns promptly to safeguard against potential exploits and ensure robust protection of sensitive data.

The Hacker News Tags:Authentication, cloud security, Cybersecurity, endpoint security, Entra ID, Malware, Microsoft, TPM systems, Vulnerability, Windows Hello

Post navigation

Previous Post: Chrome 151 Update Addresses Critical Security Flaws
Next Post: Swiss Government SharePoint Servers Hacked, 200 Accounts Affected

Related Posts

CrowdSec’s GitHub Repositories Exposed in TanStack Attack CrowdSec’s GitHub Repositories Exposed in TanStack Attack The Hacker News
Mozilla Revokes Key After Private Repo Leak Mozilla Revokes Key After Private Repo Leak The Hacker News
Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers The Hacker News
45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage The Hacker News
Adapting Security Strategies for Near-Zero Exploit Windows Adapting Security Strategies for Near-Zero Exploit Windows The Hacker News
Anthropic AI Vulnerability Risks macOS File Access Anthropic AI Vulnerability Risks macOS File Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark