Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication abuse on Windows systems. Microsoft said it has applied mitigations and that defenders should install the applicable security updates. The guidance also calls for least-privilege access, phishing-resistant authentication, and stronger endpoint protections. The advisory ties the response to a vendor CVSS 6.5 issue and a broader hardening push across authentication methods.
Related Happenings
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical Analysis
H score23
First: 04.08.2026 02:58
Last: 04.08.2026 02:58
Sources 1
How related:
Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.
About this happening:
Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical AnalysisHow related: Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.
About this happening: Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
H score3
First: 03.08.2026 19:24
Last: 03.08.2026 19:24
Sources 1
How related:
Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.
About this happening:
Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical AnalysisHow related: Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.
About this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector Action
H score38
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector ActionAbout this happening: CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)
Vulnerability
H score39
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...
Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)
VulnerabilityAbout this happening: Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...
Timeline
-
10.08.2026 15:25 2 articles · 1h ago
Microsoft applies mitigations for passkey relay assertions and CVE-2026-34348
Mitigation Patch UpdateMicrosoft said it applied mitigations for a reported passkey relay assertions issue and advised Windows defenders to install the applicable security updates for CVE-2026-34348, an information-disclosure vulnerability in the Windows Event Logging Service affecting Windows 10, Windows 11 and Windows Server. The vendor also recommended least-privilege access, phishing-resistant authentication methods, endpoint protections and a Zero Trust security model.
Show sources
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA — thehackernews.com — 10.08.2026 15:25
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA — thehackernews.com — 10.08.2026 15:25