// Alert

Microsoft Azure threat report

Security researchers disclosed Pass-the-Passkey, an attack family allowing adversaries to impersonate enterprise users and bypass phishing-resistant MFA in Windows 11 and Microsoft Entra ID. The attack exploits weaknesses in WebAuthn implementation: Windows 11 event logs exposed passkey assertion responses, and Entra ID failed to enforce anti-replay controls (challenge uniqueness, session binding, signature-counter verification). Attackers with access to logged assertions can replay them to authenticate as the original user, potentially compromising privileged accounts. Microsoft addressed the Windows logging issue (CVE-2026-34348) by truncating signatures as of July 2026, but Entra ID validation gaps remain.

// Get alerts for Microsoft Azure