Black & White Path
Aug 10, 2026 · Information Security
Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens
Researchers at Black Hat 2026 demonstrated a Pass‑the‑Passkey attack where, after gaining local code execution, an adversary reads Windows event logs to harvest WebAuthn authentication statements from a YubiKey, then replays them to Microsoft Entra ID, bypassing MFA without physical key possession.
Authentication ReplayMicrosoft Entra IDPass-the-Passkey
0 likes · 4 min read
