Enterprise passkey security under threat from malware
Summary
Researchers at Palo Alto Networks discovered attacks called Pass-ta-key that exploit weaknesses in how passkeys (passwordless authentication methods that replace passwords) are implemented, not flaws in passkey technology itself. These attacks require malware to already be installed on a victim's device and can bypass user verification requirements and extract passkey private keys (the secret codes that unlock accounts). The core issue is that organizations implementing passkeys haven't properly validated security checks around onboarding, account recovery, and device trust workflows.
Solution / Mitigation
Consultant Brian Levine explicitly recommends: "On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response." IDC analyst Frank Dickson advises: "Stop treating verification as optional. Flip it to required, check it server side" (validate on the server, not just the user's device). The source also indicates CISOs should focus on testing processes based on the assumption that "user behavior is not always as expected."
Classification
Original source: https://www.csoonline.com/article/4205751/enterprise-passkey-security-under-threat-from-malware-2.html
First tracked: August 6, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%