This week in scams and cybersecurity news,
Passkeys are increasingly replacing passwords because they offer stronger protection against phishing and stolen credentials. But new research shows that malware already running on a device could potentially interfere with certain synced passkeys and hijack protected accounts.
That does not mean passkeys are broken or that people should stop using them. Instead, the research highlights an important distinction: strong account security still depends on the security of the device holding your credentials.
Here’s what researchers found, whether passkeys remain safe, and how to protect your accounts.
Can Malware Bypass Your Passkeys?
Researchers at Palo Alto Networks recently demonstrated several attack methods targeting Google-synced passkeys used through Chrome on Windows devices.
According to SecurityWeek, these techniques could allow malware already installed on a computer to impersonate a trusted device or obtain authentication information needed to access certain passkey-protected accounts.
Key takeaways
The device must already be infected. An attacker cannot steal your passkey simply by sending you a phishing text or email.
The research focused on synced passkeys. These credentials are encrypted and synchronized across compatible devices through a cloud account.
Malware may be able to impersonate a trusted device. Researchers demonstrated methods that could request valid authentication without producing the biometric or device-unlock prompt a user would normally expect.
More advanced techniques could potentially expose multiple synced passkeys. One method targeted sensitive information that briefly appears in browser memory during device enrollment.
Google was notified and has reportedly introduced mitigations. The findings came from controlled security research, not evidence of a widespread criminal campaign.
Are Passkeys Still Safe?
Yes. Passkeys remain more resistant to phishing than traditional passwords.
Passkeys are tied to the legitimate website or app they were created for, so a fake login page generally cannot trick you into typing or handing over the credential. They also eliminate the risks created by weak and reused passwords.
This research points to a different threat: malware already operating on your device may try to abuse the systems that store, synchronize, or approve your credentials.
Think of it this way: a stronger lock still matters, but it cannot fully protect you if an intruder is already inside the house.
This Week’s Safety Tips
✓ Use passkeys when available. They still provide stronger protection against phishing and password reuse than traditional passwords.
✓ Keep your browser, operating system, and security software updated. Updates help close vulnerabilities that malware could exploit.
✓ Be cautious with unexpected files and downloads. Fake updates, email attachments, and malicious links are common ways malware reaches a device.
✓ Review your trusted devices and active sessions. Remove devices you no longer recognize or use.
How McAfee Helps Protect Your Devices and Accounts
Device security helps detect and block viruses, malware, and other threats that could compromise the device where your passkeys and passwords are stored.
Web protection helps stop risky websites and malicious downloads before they can install harmful software or steal information.
Scam Detector identifies suspicious texts, emails, and links that may try to lure you into downloading malware or visiting a fraudulent website.
Identity Monitoring alerts you if personal information connected to your accounts appears in known data breaches or on the dark web, helping you respond before it can be used for fraud.
Other Scam and Security News This Week
Meta AI model reportedly accessed another company’s systems during testing. Meta confirmed that its Muse Spark model exploited a vulnerability after a testing configuration mistakenly gave it access to the internet. The company and its evaluation partner said the incident occurred under unusual testing conditions, and Meta is continuing to investigate. (CNN)
AI-powered voice phishing reportedly targets major financial firms. Hedge funds and private equity companies were reportedly targeted with “vishing” attacks that used AI-generated voices to impersonate real people and attempt to bypass security processes. At least one company said it detected the attempt before its systems were compromised. (Bloomberg/Gizmodo)
ChainDrop malware reportedly infects more than 1,300 software packages. Researchers say the self-spreading attack compromised packages distributed through the npm software registry and attempted to steal developer, cloud, and application credentials. Organizations that installed affected versions have been advised to rotate exposed credentials and inspect their systems for unauthorized activity. (BleepingComputer)
And we’ll be back next week with more scam alerts and cybersecurity news.