Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens
Researchers at Black Hat 2026 demonstrated a Pass‑the‑Passkey attack where, after gaining local code execution, an adversary reads Windows event logs to harvest WebAuthn authentication statements from a YubiKey, then replays them to Microsoft Entra ID, bypassing MFA without physical key possession.
