Passkeys: Microsoft’s solution to 7,000 password attacks per second
Microsoft is ushering in a new era of authentication with passkeys—a modern, secure, and convenient alternative to traditional passwords.
According to statistics, Microsoft blocks up to 7,000 password attacks per second, double the rate from the previous year, while adversary-in-the-middle phishing attacks have surged by 146%. Passkeys offer a robust phishing-resistant solution by leveraging biometric authentication (such as facial recognition or fingerprints) or secure PINs, eliminating the vulnerabilities of traditional passwords. Compared to conventional passwords, passkeys are three times faster and eight times faster than passwords paired with multi-factor authentication (MFA).
Since May 2024, Microsoft has rolled out passkeys across services like Xbox, Microsoft 365, and Copilot, providing users with the option to create passkeys during sign-in or password reset processes.
Microsoft’s ultimate goal is to completely eliminate passwords, paving the way for a future that relies solely on phishing-resistant credentials such as Windows Hello and FIDO-compliant devices. With passkeys, hundreds of millions of users will benefit from enhanced protection against cyberattacks while enjoying a faster and more secure login experience.
The hacker group MUT-1244 has conducted a year-long campaign, stealing 390,000 WordPress login credentials along with many other sensitive data by using trojanized GitHub repositories to spread malware. These repositories were embedded with malicious code to steal WordPress credentials along with SSH keys and AWS access from victims, including security researchers, red team members, testers,…
Security researchers have uncovered a new Linux rootkit named PUMAKIT, featuring capabilities such as privilege escalation, file and directory hiding, and self-concealment from system tools to avoid detection. According to a report from Elastic Security Lab, PUMAKIT is an advanced Loadable Kernel Module (LKM) rootkit that leverages modern stealth mechanisms to maintain persistent connections with…
Google has released a major update for its Chrome browser, addressing three security vulnerabilities, including two high-severity memory safety flaws reported by external researchers. The most notable flaw, CVE-2024-12381, is a type confusion vulnerability in the V8 JavaScript engine, which earned the researcher who discovered it a $55,000 reward. Google stated that this flaw could…
This site uses cookies to provide you with a better user experience. For more information, refer to our Privacy & Policy