Malware running inside a user’s signed-in Windows session can invoke Windows Hello for Business keys without stealing the PIN, extracting a TPM key, or triggering biometric approval. The resulting authentication may satisfy phishing-resistant MFA and let attackers register their own device, obtain long-lived Entra ID tokens, and add credentials where tenant policies permit. Source
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!