By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Concealed RepublicanConcealed Republican
  • Home
  • Latest News
  • Guns
  • Politics
  • Videos
Reading: Hackers just breached this top login protection service. Here’s what to do
Share
Notification Show More
Font ResizerAa
Font ResizerAa
Concealed RepublicanConcealed Republican
  • News
  • Guns
  • Politics
  • Videos
  • Home
  • Latest News
  • Guns
  • Politics
  • Videos
Have an existing account? Sign In
Follow US
  • Advertise
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Concealed Republican > Blog > News > Hackers just breached this top login protection service. Here’s what to do
News

Hackers just breached this top login protection service. Here’s what to do

Jim Taft
Last updated: September 11, 2026 7:45 pm
By Jim Taft 20 Min Read
Share
Hackers just breached this top login protection service. Here’s what to do
SHARE

Remember not too terribly long ago when we recommended passkeys over usernames and passwords due to their more stringent security? Well, a new fatal flaw just emerged, and it has us rethinking our original take. Here’s what you need to know about the new passkeys vulnerability, plus what you can do to protect your data from attacks.

Well, this is awkward. We just got done saying how much better it is to use passkeys over usernames and passwords. Personally, every passkey available to me is enabled on my accounts, so maybe I’m a walking target. Perhaps you are, too, especially if your passwords are saved in Google’s software ecosystem.

Passkeys were meant to be a more perfect way to protect access to your online accounts.

This newly discovered malware — dubbed Pass-ta-key — specifically targets the passkeys system attached to Google Password Manager, the first-party password storage app built into Google Chrome and Android. The researchers who discovered the flaw hacked into Google Passkeys through the Chrome browser on a Windows PC using all three of these methods:

  • The basic Pass-ta-key exploit ultimately tricks Google’s authentication system into accessing the passkey-protected website with no identity verification (PIN, biometric data, or password) necessary.
  • Silver Pass-ta-key takes the exploit a step farther by erroneously convincing the system that the user did provide identity authentication to gain access to a website or service, treating it just like a user-confirmed event.
  • As for Gold Pass-ta-key, this top-tier exploit steals the entire passkey vault from Chrome by targeting Google’s master key system at the time a device is registered or an account is recovered.

There’s no word on whether or not other operating systems (such as macOS or Linux) and Chromium-based browsers (like Microsoft Edge and Brave) are equally susceptible, but since Windows is the largest PC platform in the world and Chrome is the most popular browser on the market, this threat puts billions of computer users at risk worldwide.

RELATED: Tired of password insanity? Make this safer, stronger choice.

Rawf8/Getty Images

Not a Windows user? You still have a reason to worry.

Apple customers aren’t out of the woods, either. A separate Apple passkey exploit was recently discovered for iCloud+ subscribers who use iCloud Private Relay, a feature meant to hide your IP address from the sites you visit online. Thanks to a WebKit bug, websites that request passkey verification may also see your IP address, even when iCloud Private Relay is enabled. The only way to stop this is to use a browser without WebKit or rely on a third-party VPN service. On the bright side, at least your passkey vaults will stay concealed.

What to do to protect yourself

Passkeys were meant to be a more perfect way to protect access to your online accounts, which is critical in an age when AI makes it easier than ever to hack systems and steal data. Despite malware like Pass-ta-key, passkeys are still more secure than traditional usernames and passwords. However, if these exploits give you pause to trust such a solution, you’re not alone. The good news is that Pass-ta-key requires pre-existing malware to already be present on the target computer, and as long as you refrain from downloading apps and services from sketchy places online, your chances of contracting this malware are on the lower side.

For those who still aren’t convinced, you might be asking yourself what you can do next to protect your accounts. Unfortunately, there aren’t many viable options left.

The truth is that it’s hard to recommend a foolproof password manager these days, as most of them have endured some kind of breach, hack, or vulnerability at one point or another. At this point, you might be better off etching your credentials on a stone tablet than putting them into a digital device. And if you don’t have one of those handy, just keep an eye on Blaze News for updates on which password exploit pops up next. We’ll report on it when we hear about it.

Read the full article here

You Might Also Like

Shadowy companies are selling access to your smart TV — and its data

Air Force Academy culminating training puts cadets through war scenario

‘You wanna get hit?’ Female purposely drives into, injures Florida resort security guard after refusing to provide ID: Cops

The FCC just banned foreign-made routers — here’s which ones might be stealing your data

Phillies vs Red Sox betting preview favors Boston through five innings despite Philadelphia’s hot streak

Share This Article
Facebook X Email Print
Previous Article New video shows what led up to Patriots fan fighting multiple Seahawks fans at NFL opener New video shows what led up to Patriots fan fighting multiple Seahawks fans at NFL opener
Next Article Muslims Hit Hardest: the Theme of the Day Again Muslims Hit Hardest: the Theme of the Day Again
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Russia’s Mach 2 Tupolev Tu-160 Bomber Is the Heaviest Combat Aircraft Ever Built and Carries Up to 12 Cruise Missiles on 2 Internal Rotary Launchers. Russia Has Built About 4 New Ones in 11 Years.
Russia’s Mach 2 Tupolev Tu-160 Bomber Is the Heaviest Combat Aircraft Ever Built and Carries Up to 12 Cruise Missiles on 2 Internal Rotary Launchers. Russia Has Built About 4 New Ones in 11 Years.
News
Giuliani Torches Zohran Mamdani’s 9/11 Toxic Air Blame as Buried Records Surface [WATCH]
Giuliani Torches Zohran Mamdani’s 9/11 Toxic Air Blame as Buried Records Surface [WATCH]
Politics
Dems Panic as John Fetterman Fuels Fears of a Stunning GOP Defection [WATCH]
Dems Panic as John Fetterman Fuels Fears of a Stunning GOP Defection [WATCH]
Politics
Bernie’s Ban on Superintelligence Is a Terrible Idea (and His Other Bill Is Worse)
Bernie’s Ban on Superintelligence Is a Terrible Idea (and His Other Bill Is Worse)
Politics
Frame and Receiver Ruling May Have Ramifications Beyond ‘Ghost Guns’
Frame and Receiver Ruling May Have Ramifications Beyond ‘Ghost Guns’
News
‘You are our last hope’: 9/11 families call on Trump to reveal Saudi Arabia’s role in terror attack
‘You are our last hope’: 9/11 families call on Trump to reveal Saudi Arabia’s role in terror attack
News
© 2025 Concealed Republican. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?