Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication abuse on Windows systems. Microsoft said it has applied mitigations and that defenders should install the applicable security updates. The guidance also calls for least-privilege access, phishing-resistant authentication, and stronger endpoint protections. The advisory ties the response to a vendor CVSS 6.5 issue and a broader hardening push across authentication methods.

Related Happenings

Pass-ta-key attacks against Google Password Manager on Windows TPM devices

Technical Analysis
H score23 First: 04.08.2026 02:58 Last: 04.08.2026 02:58 Sources 1

How related: Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.

About this happening: Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis
H score3 First: 03.08.2026 19:24 Last: 03.08.2026 19:24 Sources 1

How related: Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.

About this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

CERT-In issues 12-hour patch guidance for Indian organizations

Public Sector Action
H score38 First: 26.05.2026 13:30 Last: 26.05.2026 13:30 Sources 1

About this happening: CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...

Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)

Vulnerability
H score39 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...

Timeline

  1. 10.08.2026 15:25 2 articles · 1h ago

    Microsoft applies mitigations for passkey relay assertions and CVE-2026-34348

    Mitigation Patch Update

    Microsoft said it applied mitigations for a reported passkey relay assertions issue and advised Windows defenders to install the applicable security updates for CVE-2026-34348, an information-disclosure vulnerability in the Windows Event Logging Service affecting Windows 10, Windows 11 and Windows Server. The vendor also recommended least-privilege access, phishing-resistant authentication methods, endpoint protections and a Zero Trust security model.

    Show sources