Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
Microsoft warns: attackers are now weaponizing passkey update prompts to phish employees and hijack Microsoft 365 accounts.

Why it matters
As enterprises adopt passkeys and MFA for security, attackers are exploiting the update friction itself—a new social-engineering vector that practitioners need to brief employees on immediately.
The key facts
7 to knowAttackers using passkey/MFA update requests as phishing lure
Target: Microsoft 365 session hijacking and data access
Attack vector exploits employee trust in legitimate security prompts
Implications for enterprise authentication strategy and employee training
Target: Microsoft 365 data access and session hijacking
Attack vector: social engineering exploiting legitimate security workflows
Implies broader risk: security features creating new pretexts for compromise
Go to the source
TechRepublictechrepublic.com
Publisher excerpt: Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.