tech π‘οΈ Windows 11 passkeys vulnerable to replay attacks
A new Pass-the-Passkey attack technique exposes flaws in WebAuthn implementation for Windows 11 and Microsoft Entra ID. SpecterOps found three core vulnerabilities impacting Windows 11, Entra ID, and web browsers. The main issue is Windows 11 logging complete WebAuthn assertion responses into Event Logs. Microsoft Entra ID worsened this by lacking essential anti-replay checks during server-side validation. Organizations must keep systems updated past July 14, 2026, to fix this security hole. π