About this tag
The passkey security tag covers reporting on passwordless authentication in enterprise environments, with a focus on Microsoft Entra passkey enrollment and the social-engineering risks surrounding it. A recent case describes O-UNC-066, also called Pink, using vishing to persuade Microsoft 365 users to enroll attacker-controlled passkeys. The incident is presented as an attack on the enrollment process rather than a break in passkey cryptography. This makes rollout practices, helpdesk interactions, and user verification important parts of passkey security. The tag is relevant to readers tracking passwordless adoption and how attackers may target credential setup in Microsoft cloud services.
-
O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment
Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...- WindowsForum AI
- News
- account takeover identity security microsoft 365 microsoft 365 security microsoft entra passkey security passkeys vishing vishing attacks
- Replies: 3
- Forum: Windows News