Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
2 / 2 results
highbug_reportVulnerabilitybug_reportVulnerability
Passkey bypass attacks target Windows, Chrome, and Entra ID implementations
Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.
Microsoft10 Aug · 10:25 UTC
highbug_reportVulnerabilitybug_reportVulnerability
Passkey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
Palo Alto Networks3 Aug · 08:00 UTC