Updated
Updated · Computerworld · Aug 6
Palo Alto Details 3 Pass-ta-key Attacks on Enterprise Passkeys After Malware Intrusions
Updated
Updated · Computerworld · Aug 6

Palo Alto Details 3 Pass-ta-key Attacks on Enterprise Passkeys After Malware Intrusions

3 articles · Updated · Computerworld · Aug 6

Summary

  • Palo Alto Networks' Unit 42 outlined three malware-driven "Pass-ta-key" attack paths that can seize passkey-protected enterprise accounts, bypass user verification and extract synced private keys once an endpoint is compromised.
  • The report says the attacks exploit onboarding, recovery and device-trust workflows—not passkey cryptography itself—and in one case can take over a Google-synced passkey account without privilege escalation, device unlock or user interaction.
  • Analysts said the findings are significant because many enterprises now use passkeys as a first step toward passwordless logins, while legacy and virtualized environments often leave implementation gaps around verification and recovery.
  • Security advisers urged CISOs to require and server-side validate the user-verified flag, tighten enrollment and recovery processes, and reserve device-bound hardware keys such as YubiKeys for privileged or sensitive accounts.
  • The broader warning is that synced passkeys reintroduce credential portability risk: phishing-resistant authentication weakens quickly after a successful endpoint breach unless post-compromise controls and support processes are hardened.

Insights

Should high-risk accounts abandon synced passkeys for hardware-bound keys as recovery workflows become the real weak link?
If malware lands on a device, can a passkey-protected account still be taken over without biometrics or user interaction?