News, news analysis, and commentary on the latest trends in cybersecurity technology.
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
July 22, 2026
Attackers can exploit flaws in Microsoft's passkey systems in ways surprisingly similar to old password attacks, but that doesn't mean it's time to give up on passkeys.
There's been a lot of attention on passkeys in recent years. They're considered phishing-resistant, and their use of private keys means they are largely unaffected by data breaches where identity information and credentials are stolen. They also require zero memorization compared to traditional passwords because users embed authentication directly into the device by enabling biometrics or PINs. Even so, widespread adoption has been gradual.









