How Hackers Are Weaponizing Passkeys in 2026?

Follow Us on Your Favorite Podcast Platform
Got a message to share? For only $25, you can sponsor a podcast on any topic you love and get featured on Spotify, Apple Podcasts, Amazon, and more than 30 podcast sites!

Cybersecurity in 2026 has entered a radically different era.

Software vulnerabilities can now be analyzed and weaponized at extraordinary speed, AI-generated phishing campaigns are becoming harder to recognize, and identity has emerged as one of the most valuable targets inside the modern enterprise.

In this episode, Mike and Susan examine a troubling cybersecurity paradox: the same industry-wide shift toward stronger authentication is creating new opportunities for sophisticated social engineering attacks.

They explore why organizations are moving away from passwords, SMS codes, and voice authentication toward phishing-resistant passkeys—and how attackers are exploiting the confusion and urgency surrounding that transition.

You’ll hear how attackers can:

• Target employees through personal phones that sit outside traditional corporate security controls

• Impersonate IT support during legitimate passkey migration campaigns

• Use adversary-in-the-middle techniques to capture credentials and authenticated sessions

• Abuse device-code authentication flows to gain account access

• Register rogue MFA devices to establish persistent access

• Use Microsoft Graph API activity to map users, permissions, administrators, SharePoint sites, and mailboxes

• Slowly exfiltrate sensitive information while attempting to blend into normal enterprise traffic

The conversation also examines the growing role of artificial intelligence on both sides of cybersecurity. Attackers can use AI to accelerate vulnerability research and create more convincing social engineering campaigns, while defenders increasingly depend on behavioral analysis to identify automated reconnaissance and unusual API activity.

The result is a security environment where cryptography may become stronger while human behavior remains a critical attack surface.

If you work in cybersecurity, IT, identity management, cloud security, or enterprise risk, this episode offers a detailed look at how authentication attacks are evolving—and why securing identity now requires more than simply replacing passwords.

Listen to the full episode, subscribe for future conversations, and share it with someone responsible for protecting users, identities, or cloud environments.

Share this Podcast:

More Podcasts

Scroll to Top
Receive the Latest Podcast Right in Your Mailbox

Subscribe To Our Weekly Newsletter