Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Windows Hello Keys for Entra ID Access

Malware Exploits Windows Hello Keys for Entra ID Access

Posted on August 7, 2026 By CWS

A recent finding by researcher Dirk-jan Mollema has unveiled a potential security flaw in Windows systems, where malware, once active in a signed-in session, can exploit Windows Hello for Business keys to gain access to Microsoft Entra ID. This vulnerability allows attackers to achieve persistent access without needing administrator privileges, highlighting a significant concern in endpoint security.

Understanding the Exploit

The vulnerability, demonstrated by Mollema, involves malware using the victim’s Windows Hello for Business key to authenticate with Microsoft Entra ID. This method does not require extracting private keys, recovering PINs, or triggering biometric prompts. Instead, the system’s ticketing behavior maintains private-key operations accessible during interactive sessions.

This approach allows malicious code to request Windows to sign authentication data, effectively enabling unauthorized access. The attack requires the malware to execute within an active session, leveraging how Windows Hello for Business operates. Importantly, no current reports of active exploitation or specific victim cases have been documented.

Implications for Cloud Access and Device Registration

By exploiting this vulnerability, attackers can secure prolonged cloud access, register new devices under their control, and even obtain a Primary Refresh Token (PRT). This token can be continuously renewed, granting ongoing cloud service access for up to 90 days, provided the user remains active.

Mollema further demonstrated that the technique bypasses prior requirements by treating Windows Hello for Business keys as FIDO2 passkeys through WebAuthn. This new method allows an attacker to generate the necessary signed assertions on a compromised endpoint, facilitating unauthorized access to Microsoft cloud services.

Security Measures and Recommendations

To mitigate this potential threat, Mollema advises monitoring for unexpected device registrations and scrutinizing Windows Hello for Business sign-ins that lack a device ID. Such patterns could indicate unauthorized access attempts. Despite the absence of a CVE or official advisory from Microsoft, staying vigilant and employing robust security policies is crucial.

Microsoft’s documentation acknowledges the ticketing behavior, but the lack of immediate corrective action underscores the need for organizations to implement supplementary security measures. Detection of suspicious activity and adherence to strict Conditional Access policies can serve as effective deterrents against such exploits.

The research, including PowerShell proof-of-concept scripts, is available for cybersecurity professionals aiming to understand and counteract this vulnerability. It is essential to address these concerns promptly to safeguard against potential exploits and ensure robust protection of sensitive data.

The Hacker News Tags:Authentication, cloud security, Cybersecurity, endpoint security, Entra ID, Malware, Microsoft, TPM systems, Vulnerability, Windows Hello

Post navigation

Previous Post: Chrome 151 Update Addresses Critical Security Flaws
Next Post: Swiss Government SharePoint Servers Hacked, 200 Accounts Affected

Related Posts

Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws The Hacker News
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware The Hacker News
Espionage Campaigns Target Pakistani Police Portals Espionage Campaigns Target Pakistani Police Portals The Hacker News
Digital Parasite Threats Redefine Cybersecurity in 2026 Digital Parasite Threats Redefine Cybersecurity in 2026 The Hacker News
New LOTUSLITE Variant Targets Indian Banks and South Korean Policy New LOTUSLITE Variant Targets Indian Banks and South Korean Policy The Hacker News
Linux KVM Bug Risks Host Security on Intel and AMD Linux KVM Bug Risks Host Security on Intel and AMD The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark