Home / Aug 09, 2026 / Story
0
#10 The Hacker News general August 07, 2026 at 08:52 UTC

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

By [email protected] (The Hacker News)

AI Summary

Security research disclosed at Black Hat USA 2026 shows that malware can abuse Windows Hello for Business cryptographic keys to maintain persistent access to Microsoft Entra ID, surviving credential resets that defenders typically rely on for eviction. This technique undermines a common incident response step and is relevant to any enterprise using Entra ID with passwordless authentication.

Relevance score: 72.0/100

# More from August 09