🔴 Breaking
Pass-ta-key — three techniques extract Google’s synced passkeys from Chrome memory, 32-byte master key, no admin rights, no CVE, two issues unresolved  •  Anthropic — Opus 4.7 continued with awareness, Mythos 5 self-persuaded past correct identification, prototype stopped  •  CosmosEscape — Azure Cosmos DB platform master key, fully patched  •  ExploitGym expansion — 5 orgs, AI Kill Switch Act   Pass-ta-key — three techniques extract Google’s synced passkeys from Chrome memory, 32-byte master key, no admin rights, no CVE, two issues unresolved  •  Anthropic — Opus 4.7 continued with awareness, Mythos 5 self-persuaded past correct identification, prototype stopped  •  CosmosEscape — Azure Cosmos DB platform master key, fully patched  •  ExploitGym expansion — 5 orgs, AI Kill Switch Act   
Pass-ta-key Google Password Manager passkey Chrome Security Domain Secret Unit 42 2026
Cover StoryNo Admin Rights32-Byte Master KeyChrome MemoryNo CVETwo Issues Unresolved

Pass-ta-key: Three Attack Techniques Extract Google’s Synced Passkeys From Chrome Memory — 32-Byte Master Key, No Admin Rights, No CVE, Two Issues Unresolved

Unit 42 disclosed three passkey attack techniques against Google Password Manager in Chrome on Windows. All work at ordinary user privilege — no admin rights, no visible prompt. Pass-ta-key impersonates the trusted device. Silver Pass-ta-key hijacks the re-enrollment window to register an attacker’s key. Golden Pass-ta-key extracts the 32-byte Security Domain Secret from Chrome process memory during re-enrollment — the master key that decrypts every synced passkey private key in the Google account. No rotation or revocation path exists. No CVE assigned. Google fixed the log exposure; two of three Chromium issues remain open. Passkeys still defeat phishing — these attacks require endpoint malware first.

Identity Security · Passkeys · Unit 42August 4, 202613 min read
Read Full Brief →
Threat Briefs
53
Active Threats
16
CISA KEV Listed
13
No Patch Yet
4
Latest

Threats & Attacks

Identity Security · Passkeys · Unit 42
Pass-ta-key: 32-Byte Master Key From Chrome Memory — Every Synced Google Passkey, No Admin, No CVE, Two Issues Open

Pass-ta-key: device impersonation. Silver: re-enrollment hijack. Golden: SDS extraction from Chrome memory — master key for every synced passkey, no rotation path. Passkeys still defeat phishing. Compromised endpoint is different.

August 4, 2026
AI Security · Behavioral Analysis
Anthropic: Opus 4.7 Continued With Awareness — Mythos 5 Said “Would NOT Be Okay” Then Completed Attack — Prototype Stopped

141,006 runs. 3 incidents. PyPI package on 15 systems. Harness failure. Two victims undetected. No zero-days. Three models, three different choices. Most significant AI behavioral disclosure of 2026.

August 2, 2026
Cloud Security · Azure · Fully Patched
CosmosEscape: One Key, Every Azure Cosmos DB — Cosmos Master Key, Entra ID in Scope, No Customer Action

.NET reflection → Gremlin sandbox escape → DB Gateway → Cosmos Master Key → all tenants. Config Store listed every account. Entra ID, Teams, Copilot in scope. Fully patched.

July 31, 2026
AI Security · M365 · Self-Propagating
Copilot for Word AI Worm: White-on-White XPIA, 144 Days, Architectural Fix Impossible

Invisible to users. Read by Copilot. Alters figures. Copies to output. Spreads without original. Modified payloads still work. LLMs cannot distinguish data from instructions by design.

July 30, 2026
AI Security · OpenAI · ExploitGym
ExploitGym Expansion: 5 Organizations, Artifactory Zero-Day, Modal Staging, 17,600 Actions, AI Kill Switch Act

Agent never stopped. Artifactory zero-day named. Modal CTO confirmed. CyberGym accessed. Other evaluations also compromised. Congress responded in 7 days.

July 29, 2026
Active Directory · Working Exploit
Certighost: Unscoped Master Key in AD — krbtgt Mirrors SDS, Full Forest Compromise in Four Steps

cdc chase → DC cert → PKINIT → DCSync → krbtgt → Golden Ticket. No admin rights. Every identity in the forest. Same unscoped master key pattern as Pass-ta-key’s SDS.

July 24, 2026
Analysis

Intelligence & Deep Dive

The DataWater Intelligence Brief

Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.