You were told passkeys would end the phish. Vendors still say it. A lot of boards already filed identity under “done.” Microsoft’s incident write-up this week should wreck that comfort. Attackers are running passkey-themed social engineering, coaching people through a setup that looks like IT, then riding the new factor into mail, files, and tenant recon. If your cybersecurity program still treats a phishing-resistant checkbox as closure, you’re defending a slogan.
The Enrollment Click Is the Payload Now
Stop picturing brute-force against a password, or a crude clone of a login page grabbing a six-digit code. This week’s campaigns are more patient than that. The lure talks like a required upgrade. It talks like threat-protection doing the user a favor. The victim isn’t primarily asked to surrender a secret. They’re asked to finish a ceremony that looks like cyber security hygiene.
When that registration sticks, the attacker owns an authentication method inside your identity platform. The factor lives next to the ones you issued on purpose. Helpdesk resets and “just change the password” rituals leave it sitting there. That’s MFA persistence, and it’s why this is a tenant incident rather than a messy inbox.

The protocol can be sound and the user can still get coached into enrolling the wrong authenticator. Phishing-resistant MFA works when the ceremony is bound to the real origin and nobody is walking the victim through a second enrollment on a call, in chat, or on a “setup required” page. The themed lure attacks the coaching. It attacks the trust. It attacks the habit of clicking Continue because the prompt looks official.
Expect the targets to be whoever can register a method without a fight: executives who treat every security banner as mandatory, contractors who never saw your enrollment policy, helpdesk-adjacent staff who live inside identity tickets all day. You already trained people to take passkey prompts seriously. Operators noticed.
Password Reset Will Not Close This Incident
If your incident response runbook still ends at “force a password change and revoke refresh tokens,” the runbook is incomplete. You need a method inventory. Pull every passkey, security key, authenticator app, app password, trusted device, and forwarding rule that appeared in the same window as the suspicious login. Treat an unexpected FIDO credential the way you’d treat a new Global Admin role: hostile until you can prove otherwise.
Microsoft’s follow-on activity is the part your SOC should pin to the wall. After the identity lands, operators abuse Microsoft Graph for reconnaissance, then reach SharePoint, OneDrive, and email. That’s API-shaped theft. It looks like a user having a busy afternoon. Threat detection that only watches endpoints will miss it. Defense in depth that stops at the firewall will miss it. The session is valid. The factor is registered. Your cloud audit logs are the crime scene.
Your Cybersecurity Queue Is Already Full
Identity isn’t the only control plane getting abused while you congratulate yourself for MFA. Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center. That’s the console that defines policy for the estate, not a random packet filter. If someone else is driving FMC, they don’t need to beat your firewall. They are the firewall.

SANS ISC, same week, is watching scans for a bug in Proxmox VE 7. That major version has been unsupported for years. Scanners don’t care that your upgrade project is “on the roadmap.” They care that an old hypervisor management interface still answers.
Dark Reading’s look at Project Glasswing and the Mythos findings puts a name on the bottleneck you already feel. Only a fraction of discovered bugs reach disclosure. A thinner slice get fixed. The firehose is real. The humans on the other end are not infinitely scalable. Social engineering doesn’t wait for a CVE. Neither do the people fingerprinting EOL labs.

The real problem here is attention. You do not have a spare sprint to debate whether passkeys “solved phishing” while the firewall manager is a live exploit target and forgotten hypervisors are getting probed. Human-paced patching is a queue. Enrollment abuse jumps the queue because it uses a control you already told users to trust.
Hunt the Method, Not the Malware
Do the identity work this week. Then keep doing it, because a one-time audit is how last quarter’s unknown passkey becomes next quarter’s quiet mailbox dump. Security hardening here is mostly policy, logging, and eviction, not another box on the perimeter.
- Export every authentication method registered in the last 30 to 90 days. Flag passkeys, security keys, and authenticator apps added outside a known rollout window, especially on privileged accounts and shared mailboxes that should never enroll anything.
- Page a human on “strong authentication method registered” and “device registered” for admins. Near real time. A weekly review is how persistence ages into background noise.
- Contain like a credential incident, not a malware incident. Revoke sessions, disable or tightly step-up the account, delete unknown methods, then hunt inbox rules, consent grants, SharePoint download spikes, and Graph enumeration from unfamiliar device IDs or ASNs.
- Pull FMC and any other firewall managers off the public internet. Patch. Review admin logs for unfamiliar policy publishes and new local accounts. If the manager was reachable, assume someone tried it.
- Inventory hypervisors the same way you inventory domain controllers. If Proxmox 7 is still alive, isolate its management NIC and treat the upgrade as incident response, not a project plan.
- Rewrite the helpdesk script in public language users will remember: nobody from IT will ask you to add a passkey, scan a QR, or “finish enrollment” on a cold call or in chat. Then test the helpdesk. If they still walk callers through enrollment, your control is theater.
Ongoing, lock down who can register a method, from which networks, and only after an already-good factor. Baseline Graph and file-access volume per role so “busy afternoon” has a number attached. Put identity-method changes in the same tier-1 threat detection bucket as new privileged roles. That’s the unglamorous version of defense in depth: the cloud identity plane gets the same suspicion you already give a new VPN tunnel.
Frequently Asked Questions
- Aren’t passkeys supposed to be phishing-resistant?
- The origin-bound ceremony is. The human who can be talked into a second enrollment on a fake IT ticket is not. Microsoft’s cases go after that coaching layer, then keep the resulting factor for persistence.
- If we reset the password, is the incident closed?
- No. A registered passkey, app, or trusted device can outlive the password. Close the incident only after method inventory, session revocation, rule and consent review, and a controlled re-enrollment you initiate.
- Why should identity teams care about FMC or an old hypervisor this week?
- Because your queue is finite. While you’re arguing about MFA branding, people are exploiting firewall managers and scanning EOL Proxmox. Shrink those control planes so identity incidents aren’t competing with preventable management-plane fires.
Sources
- Passkey-themed social engineering leads to identity and cloud compromise
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
- Mythos Vulnerability Firehose Hits a Human Bottleneck
- Scans for Proxmox Servers
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
