
Microsoft Identifies Phishing Campaigns Exploiting Passkeys to Compromise Cloud Identities
hacker attacksmalwarenewscyber securityprivacyapplicationsclouddigital identityinfrastructureMicrosoftpasswordphishingsecurity awarenesssocial engineering
Microsoft has identified phishing campaigns exploiting passkeys as a pretext to make attacks more credible. Attackers are using fake security update notifications to compromise Microsoft cloud identities. The campaigns enable attackers to gain persistence and access Microsoft 365 resources. While passkeys are resistant to phishing, threat actors are leveraging them as a social engineering lure to trick users into compromising their accounts.