Passkey Security: Are Your Credentials at Risk? Insights from Black Hat 2026
Are passkeys as secure as you think?
Are Passkeys Still Secure? Understanding the Latest Research
Passkeys have been heralded as the “death of the password” and a gold standard for phishing-resistant authentication. However, recent research presented at Black Hat USA 2026 has sparked concern: Can passkeys be bypassed?
The short answer is that while the underlying cryptography of passkeys remains robust, researchers have identified ways to defeat the *implementations* of these systems on Windows and within cloud-synced services. These attacks do not “break” FIDO2 math; instead, they exploit how operating systems and cloud services handle authentication material.
What Did the Researchers Find?
Three separate research efforts have highlighted potential vulnerabilities:
Replay Attacks (SpecterOps): Researchers demonstrated that Windows stored past YubiKey signatures in cleartext, allowing attackers to replay these signatures to impersonate privileged users in Microsoft Entra ID.
Synced Key Recovery (Unit 42): Investigations into Google Password Manager on Windows revealed paths that could potentially recover private keys for synced passkeys.
Session Hijacking (Dirk-jan Mollema): Malware running in an active, signed-in Windows session could potentially leverage a hardware-bound Windows Hello for Business key without requiring a fresh PIN or biometric verification.
How Can You Protect Your Organization?
These findings demonstrate that no single security control is a silver bullet. At The Digital Guardrail, we advocate for a “Defense-in-Depth” strategy.
Apply Updates Immediately: Microsoft has released patches (such as CVE-2026-34348) to address the Windows Event Logging vulnerability. Ensure your patch management cycle is rigorous.
Embrace Zero Trust: Do not rely solely on authentication tokens. Implement continuous verification for every access request.
Adopt Least-Privilege Access: Limit the blast radius of a potential compromise by strictly controlling who has access to sensitive systems.
Endpoint Protection: Since many of these attacks require malware to be present on the host machine, robust EDR (Endpoint Detection and Response) is non-negotiable.
Frequently Asked Questions
Are passkeys still safe to use?
Yes. Passkeys remain significantly more secure than traditional passwords. These attacks target specific implementation flaws, not the FIDO2 standard itself.
Should I stop using passkeys?
No. The risk of credential theft via phishing far outweighs the risk of these highly specialized, complex bypass methods.
How does The Digital Guardrail help?
We help organizations audit their authentication workflows and implement Zero Trust architectures that mitigate the risks of credential replay and session hijacking.
Don’t leave your organization’s identity security to chance. Contact The Digital Guardrail today for a comprehensive security assessment.

