PC HARDWARE Apple M6 Benchmarks Show Multi-Core Power Rivaling M3 Max LINUX Wardogs Early Access sells 1M copies, breaks servers on launch NINTENDO SWITCH 2 Wo Long 2: Wings of Ember Launches March 4, 2027, with Xbox Game Pass Day One AMD Micron 512GB DDR5 RDIMM: 9,200 MT/s speeds and 60% less power GAMES Halo 5: Guardians Single-Player Campaign Ported to PC by Fan PC HARDWARE MediaTek Dimensity 9600 Pro Benchmarks Show 40% Efficiency Gain GAMES Diablo 4 Season of Hell’s Legacy Adds Hidden Diablo 2 Runewords AMD AMD RDNA 5 Neural Lighting Rumored as DLSS 5 Rival ACCESSORIES Razer Brings Sensa HD Haptics to Kraken V4 X for $99.99 CONSOLES Sony PS4 Update 14.00 Released: Stability and Performance Fixes GAMES Entergram Announces Azure Memoria Console Game Starring Azusa Honami AMD HP ZBook Ultra G3a brings 192 GB RAM and 16-core Ryzen AI to mobile workstations PLAYSTATION 5 Sonic Racing CrossWorlds Adds Bayonetta as Free Character NINTENDO SWITCH 2 Diablo IV Season 15 Delayed After Widespread Login Errors Hit Switch 2

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11

Owen Carter 2 min read

Microsoft patched CVE- 2026- 34348, a passkey reuse vulnerability in Windows 11 and Entra ID, to prevent credential replay attacks in enterprise environments.

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11
SOFTWARE AND UPDATES

Microsoft closed a critical security gap in its passkey infrastructure on July 14. This patch protects enterprise environments from attacks that bypass traditional password requirements. Users relying on FIDO2 keys for single sign-on now have a verified fix for a flaw that allowed credential reuse.

Enterprise identity management requires strict enforcement of modern authentication standards

The vulnerability, tracked as CVE-2026-34348, targeted the interaction between Windows 11 and Microsoft Entra ID. Security researcher Michael Grafnetter demonstrated how an attacker could exploit this setup during a presentation at Black Hat USA. The attack, dubbed 'Pass-the-Passkey,' allowed unauthorized access without the victim's actual password.

Grafnetter found that Windows 11 logged full copies of passkey material, creating a local security risk. Microsoft Entra ID failed to prevent the reuse of these captured keys across different sessions. The cloud-side flaw specifically enabled attackers to replay valid authentication tokens generated by legitimate users.

Microsoft addressed the cloud-side vulnerability on July 14 to stop the token replay attacks. The fix primarily impacts enterprise deployments that use Entra ID for identity management. Organizations should verify that their FIDO2 key implementations are updated to prevent legacy password logins.

Passkeys remain a more secure alternative to passwords when configured correctly. The vulnerability highlights the need for strict enforcement of modern authentication standards. Enterprises must disable legacy password options to fully benefit from the security improvements.

Source: Pass-the-Passkey, NotebookCheck