#Passwordless Authentication

Every story tagged Passwordless Authentication, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

1 story · open in the command center

  • Security & PrivacyHacker News3m

    Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    Researchers have discovered three novel attack classes (Pass-ta-key exploits) that compromise passkey-protected accounts through malware on compromised endpoints, enabling account takeover without user interaction, bypassing device unlock requirements, and extracting synced passkeys for credential trafficking. While passkeys eliminate traditional password-based attacks, this research reveals that defenders must prepare for a new generation of attacks targeting the implementation and synchronization mechanisms of passwordless authentication systems. For IT organizations, this represents a critical security paradigm shift requiring enhanced endpoint protection, monitoring of authentication workflows, and re-evaluation of zero-trust assumptions around passkey-based identity systems.

Browse all tags