SpecterOps presented Pass-the-Passkey at Black Hat USA 2026, showing that Windows stores YubiKey signatures in cleartext, enabling privileged-user impersonation via Microsoft Entra ID. The research led to CVE-2026-34348 and Microsoft mitigations.
SpecterOps presented Pass-the-Passkey at Black Hat USA 2026, showing that Windows stores YubiKey signatures in cleartext, enabling privileged-user impersonation via Microsoft Entra ID. The research led to CVE-2026-34348 and Microsoft mitigations.