Sunday, August 9, 2026
HomeTechnologyEnterprise passkey safety beneath risk from malware – Computerworld

Enterprise passkey safety beneath risk from malware – Computerworld

-



The Palo Alto report confirmed assaults that, it stated, “exhibit how malware on a compromised endpoint can misuse onboarding, restoration and system belief workflows to take over passkey-protected accounts,” in addition to “how an attacker can authenticate with out person interplay, bypass person verification necessities and extract all synced passkey personal keys.”

Palo Alto described three classes of assault, collectively dubbed Cross-ta-key: Cross-ta-key, the place an attacker takes over an account protected by a Google-synced passkey utilizing malware working on the sufferer’s system, with out requiring privilege escalation, system unlock or person interplay; Silver Cross-ta-key, which entails an attacker tricking Google Cloud Authenticator into believing the sufferer has unlocked the system with biometrics, resulting in full account takeover with out utilizing the sufferer’s system throughout authentication; and Golden Cross-ta-key, which permits an attacker to extract all synced passkeys in a kind that lets them be shared or bought on the credential black market.

Given the complexity of most international enterprise risk surfaces, some CISOs have struggled with adapting passwordless processes to environments with legacy and digital environments. Passcodes have been just lately embraced by enterprise CISOs as step one in implementing a passwordless technique.

Related articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
0FollowersFollow
0FollowersFollow
0SubscribersSubscribe

Latest posts