Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys. The firm says chaining those signatures with weaknesses in Microsoft Entra ID's passkey validation allowed privileged-user impersonation despite policies requiring phishing-resistant MFA. Borrowing Windows Hello without the PINMollema's research focuses on Windows Hello for Business. Those surrounding controls can still leave attackers with reusable assertions, synced passkey private keys, or a way to generate fresh authentication from a compromised Windows session. Entra defenders can also monitor unusual Windows Hello for Business authentications without a device identifier and unexpected device registrations.