Web Hack List

Preliminary research

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Investigates cloud passkey recovery after compromise of device identity. Forced re-onboarding permits an attacker-controlled user-verification key to be registered in a pending state, supporting later remote assertions; separate sync-secret logging and recovery-memory paths illustrate how authenticator state changes the post-compromise boundary.

Record

Researcher
Arie Olshtein
Published by
Palo Alto Networks Unit 42
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Arie Olshtein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .