<div cla
Every August, Black Hat and DEF CON turn Las Vegas into what security people only half jokingly call hacker summer camp. This year the nickname earned itself twice over. This week a Delta flight out of Las Vegas landed under investigation for an unauthorized Wi-Fi network onboard, reportedly the work of DEF CON attendees testing gear at 30,000 feet. Delta says no actual aircraft system was compromised, but the timing made it a fitting mascot for the week’s real headline. Black Hat USA 2026 ran the same week, and SpecterOps used it to present new passkey research. Two more findings, against Google Password Manager and Windows Hello for Business, surfaced in that same stretch of days. Passkeys have had two years of vendor messaging calling them phishing resistant and effectively unbreakable, and that kind of claim, at that kind of scale, is exactly what a room full of the industry’s best offensive researchers shows up to test. Together, the three findings amount to the most serious stress test passkeys have faced since enterprises started deploying them at scale.
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/new-passkey-attacks-explained-what-security-researchers-found-this-august/

