Crypto Ticker:
sysadmin from 4sysops.com

Malware can turn Windows Hello keys into persistent Entra ID access

IT News
Aug 7, 2026 at 09:59
4 Views
0 Comments
Malware can turn Windows Hello keys into persistent Entra ID access

Malware running inside a user’s signed-in Windows session can invoke Windows Hello for Business keys without stealing the PIN, extracting a TPM key, or triggering biometric approval. The resulting authentication may satisfy phishing-resistant MFA and let attackers register their own device, obtain long-lived Entra ID tokens, and add credentials where tenant policies permit. Source

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!