Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
The Hacker News
5 days ago

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

By info@thehackernews.com (The Hacker News)

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.