Enterprise passkey security is vulnerable to malware attacks, as revealed by a recent Palo Alto Networks Unit 42 report1. The report highlights that attackers can bypass passkey protections, but only after a successful intrusion has occurred. The demonstrated attacks exploit weaknesses in the procedures surrounding passkeys, rather than the underlying cryptography itself. Specifically, the vulnerabilities lie in the onboarding flows and recovery processes, which can be manipulated by malicious actors. This is a concern for enterprises that have adopted passkeys as a replacement for passwords, as it underscores the importance of securing the entire passkey ecosystem, not just the passkeys themselves. The fact that passkey security can be compromised by exploiting these seams is a significant concern, as it highlights the need for robust security measures to protect against malware attacks, so what matters most to practitioners is ensuring that their passkey implementations are thoroughly secured against such threats.