SECURITY·중요도 8·2026. 08. 10.·The Hacker News

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

── KO ──────────────────

새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.

최근 연구에서 패스키 보호를 무너뜨리는 세 가지 방법이 발표되었습니다. 이 공격들은 암호학을 해치지 않고도 패스키 시스템의 취약점을 이용합니다. 연구자들은 윈도우가 노출한 인증 자료를 재사용하거나, 피해자의 기계에 이미 존재하는 악성코드로부터 클라우드와 동기화된 패스키 시스템을 악용했습니다.


── EN ──────────────────

New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.

Recent research efforts showcased three distinct methods to defeat passkey protections without compromising the underlying cryptography. The attacks involve reusing signed authentication material exposed by Windows, exploiting a cloud-synced passkey system from malware already present on the victim's machine, and other techniques. These findings highlight vulnerabilities in current passkey systems meant to enhance security against phishing.

원문 보기 →목록으로