LIVE · cybersecurity feed
Live wire
malwarehigh

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Researchers have discovered a method for malware to abuse Windows Hello for Business keys, enabling persistent access to Microsoft Entra ID. The technique allows malicious code running within a user's active session to silently authenticate using the victim's Hello for Business key, bypassing biometric or PIN prompts on TPM-backed systems. This can lead to the attacker registering their own device, obtaining a Primary Refresh Token, and potentially adding further authentication methods, even satisfying phishing-resistant authentication requirements.

zeroday.news ·

A new report indicates that malware can exploit Windows Hello for Business keys to maintain persistent access within Microsoft Entra ID environments. This technique allows malicious software operating within an active user session to perform silent authentication using the victim's existing Hello for Business key. The method reportedly bypasses typical biometric or PIN prompts, even on systems leveraging Trusted Platform Modules (TPMs) for key protection.

The core mechanism involves malware leveraging the legitimate Windows Hello for Business key, which is typically used for passwordless authentication, to authenticate to Entra ID. By operating within an already authenticated user session, the malware can effectively impersonate the user without requiring re-authentication prompts. This circumvents the security measures usually associated with Hello for Business, which are designed to protect the key from unauthorized use by requiring user interaction.

Once the malware successfully authenticates using the compromised key, it can then proceed to register a new device under the victim's identity within Entra ID. This device registration is a critical step, as it can enable the attacker to obtain a Primary Refresh Token (PRT). A PRT grants long-lived access to Entra ID resources and can be used to request new access tokens for various services without requiring repeated user interaction.

Further implications include the ability for the attacker to add additional authentication methods to the compromised account. This could involve registering new multi-factor authentication (MFA) methods under their control, thereby solidifying their persistent access. The report also suggests that this technique could potentially satisfy phishing-resistant authentication requirements, as the initial authentication leverages a legitimate, hardware-backed key.

This class of attack highlights the importance of endpoint security and the integrity of user sessions. While Windows Hello for Business is designed to enhance security by reducing reliance on passwords and providing phishing-resistant authentication, its underlying keys can be abused if the endpoint itself is compromised by malware. Products in this category commonly rely on the operating system's integrity and the security of the user's session to protect cryptographic material.

Mitigation strategies for such threats typically involve robust endpoint detection and response (EDR) solutions to identify and prevent malware execution. Implementing least privilege principles for user accounts and regularly auditing Entra ID for unauthorized device registrations or newly added authentication methods are also crucial. Furthermore, organizations should consider advanced threat protection measures that monitor for anomalous authentication patterns and session hijacking attempts.

This finding underscores the ongoing challenge of securing modern identity systems, particularly when sophisticated malware can operate within the context of legitimate user sessions. As organizations increasingly adopt passwordless and hardware-backed authentication methods, the focus of attackers may shift to compromising the integrity of the endpoints that house these powerful cryptographic keys.

malwarewindows hello for businessentra idauthenticationvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI