New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption post, augustus 10, 2026augustus 17, 2026 Three independent security investigations have exposed weaknesses in the systems surrounding passkeys, demonstrating how attackers with access to a Windows endpoint could impersonate users, bypass phishing-resistant multifactor authentication or recover the private keys behind cloud-synchronised credentials. The findings do not undermine the public-key cryptography at the heart of FIDO2 and WebAuthn. Instead, the researchers targeted the software, cloud services, recovery processes and operating-system interfaces responsible for creating, storing and using passkeys. (10) New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption | LinkedIn: New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption vulnerability 2026