Passkey Pwned attack: How to secure against it

SquareX researchers disclosed the Passkey Pwned attack on the mainstage at DEF CON 33 earlier this August. This attack exploits malicious browser extensions to intercept authentication flows, generating attacker-controlled keys while users see legitimate biometric prompts. Organizations need comprehensive browser extension audits that go beyond point-of-installation checks. Dynamic analysis of real-time extension behavior is critical because benign extensions can turn malicious through attacker compromise or purchase after gaining user trust. Learn about enterprise mitigation strategies to secure yourself against a Passkeys Pwned attack: https://hubs.ly/Q03G8g340 #cybersecurity #browsersecurity #enterprisesecurity

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories