:

39 ATTACK METHODS FOUND IN PASSKEY SYSTEMS

SECURITY DESK1 MIN READ
SAT, SEP 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers have identified 39 distinct methods for compromising passkey authentication, exploiting weaknesses beyond the underlying FIDO2 cryptography.

While passkeys eliminate many traditional password-based attacks, the authentication systems built around them contain multiple vulnerabilities. Researchers documented attacks targeting authentication prompts, synced credentials, enrollment processes, and account recovery mechanisms. The findings reveal that attackers can exploit trust boundaries and implementation gaps without breaking the cryptographic foundation of FIDO2. Vulnerable areas include how credentials are synchronized across devices, how users enroll in passkey systems, and how accounts are recovered when access is lost. These discoveries highlight a critical distinction: passkeys provide stronger cryptography than passwords, but the broader authentication infrastructure surrounding them requires careful security design. Organizations implementing passkey systems must address these implementation-level vulnerabilities to realize the full security benefits. The research underscores that cryptographic strength alone does not guarantee secure authentication systems.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A critical remote code execution vulnerability affecting all Chromium versions is currently being exploited in the wild. The flaw bypasses the browser's sandbox protection, allowing attackers to execute arbitrary code with full system access.

5H AGOSecurity Desk

Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.

9H AGOIndustry Desk

Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.

12H AGOSecurity Desk

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.

14H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.