رفتن به محتوای اصلی
بازگشت به اخبار
اخبار امنیت (RSS) منبع: هکر نیوز

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

۱۴۰۵/۰۵/۱۸
اخبار امنیت (RSS)
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

این خبر از منبع خارجی «هکر نیوز» بازنشر شده است.

برای مطالعه متن کامل به صفحه اصلی خبر مراجعه کنید.

مشاهده منبع اصلی