Find notable cyber news and cases, enriched with sources, timelines, and signals.

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis
First reported
Last updated
Happening score
H score 3
1 unique sources, 2 articles

Summary

Hide ▲

Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate passkey handling without breaking cryptography. The newer reporting says the strongest path can recover the 32-byte Security Domain Secret (SDS) for synced passkeys, while related findings from SpecterOps and Dirk-jan Mollema show other post-compromise ways to reuse signed authentication material or a Windows Hello for Business key. The combined event remains centered on endpoint compromise and the surrounding controls that can still leave attackers with reusable authentication material.

Related Happenings

Google Cloud ships quantum-safe key exchange and publishes post-quantum migration roadmap

Security Tool/Service
H score11 First: 13.08.2026 18:00 Last: 13.08.2026 18:00 Sources 1

About this happening: Google Cloud has begun rolling out quantum-safe key exchange and a staged post-quantum migration roadmap, expanding cryptographic protections for cloud services ahead...

OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw

Vulnerability
H score36 First: 12.08.2026 14:47 Last: 12.08.2026 14:47 Sources 1

About this happening: A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys...

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
H score31 First: 10.08.2026 15:25 Last: 10.08.2026 15:25 Sources 1

How related: "We appreciate the work of SpecterOps for reporting this through a coordinated vulnerability disclosure. We have applied mitigations for the reported issue involving passkey relay assertions and continue investing in security enhancements across authentication methods. We recommend adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected,"

About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...

Palo Alto Networks Pass-ta-key analysis of passkey-hijack attack methods

Technical Analysis
H score26 First: 05.08.2026 15:48 Last: 05.08.2026 15:48 Sources 1

About this happening: Palo Alto Networks disclosed Pass-ta-key, a new set of attack methods that lets malware on Windows machines running Chrome hijack Google-synced passkeys and ta...

Pass-ta-key attacks against Google Password Manager on Windows TPM devices

Technical Analysis
H score23 First: 04.08.2026 02:58 Last: 04.08.2026 02:58 Sources 1

How related: Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.

About this happening: Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...

Timeline

  1. 03.08.2026 19:24 3 articles · 13d ago

    Unit 42 details three Chrome Google Password Manager passkey attack paths

    Initial Disclosure

    Palo Alto Networks Unit 42 detailed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key against Chrome's Google Password Manager on Windows systems with a Trusted Platform Module (TPM), showing how malware already running on the victim's device can obtain a valid assertion, register an attacker-controlled user-verification key, or extract the 32-byte Security Domain Secret (SDS) used to decrypt synced passkey private keys. The techniques are described as post-compromise paths that do not break the underlying cryptography and can enable reusable access after an initial endpoint compromise.

    Show sources