Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities SC Media

German government report details Windows Hello for Business biometric security limitations

  • What: German government report details security limitations in Windows Hello for Business
  • Impact: Enterprise users may face risks if Enhanced Sign-in Security is not enabled
Read Full Article →

Identity , IAM Technologies , Threat Intelligence German government report details Windows Hello for Business biometric security limitations July 28, 2026 Share By SC Staff (Adobe Stock) Germany’s Federal Office for Information Security (BSI) published a technical analysis of Windows Hello for Business, detailing how the system performs biometric identification and highlighting potential security vulnerabilities. The study, conducted by ERNW on behalf of the BSI, utilized debugging and reverse engineering techniques to examine the internal processes of Windows 10 Enterprise LTSC 2021, with a specific focus on facial recognition, as first reported by Biometric Update. The BSI report identifies limitations in Windows Hello for Business when Enhanced Sign-in Security (ESS) is not enabled. While the Trusted Platform Module (TPM) can protect the enterprise authentication key, it does not fully secure all biometric data and processes. The study found that the information required to access the encrypted biometric template database is available on the same computer, creating a gap where a privileged attacker could potentially modify enrollment records. This could allow an attacker to associate a different user's identity with a successful biometric match. Furthermore, the research revealed that the system could be vulnerable to presentation attacks, as demonstrated by the successful enrollment and authentication using a facial mask. Degraded enrollment conditions, such as enrolling with accessories like scarves and glasses, also led to incorrect authentications by another individual. The report emphasizes that the overall security of biometric authentication relies heavily on device configuration, hardware, enrollment permissions, local administrator access control, and the implementation of ESS. Source: Biometric Update SC Staff Related Identity Scammers impersonate ShinyHunters in new sextortion email campaign SC Staff July 27, 2026 Following insights from Bleeping Computer, threat actors are leveraging email addresses exposed in data breaches, previously leaked by the ShinyHunters extortion group, to perpetrate a new sextortion email campaign demanding $2,000 in Bitcoin. Data Security Pope’s prayer app leaks 700,000 user emails SC Staff July 27, 2026 The Click To Pray app, endorsed by the Pope and used by hundreds of thousands worldwide, was leaking user names and email addresses for months. Data Security OnTrac parcel delivery company reports customer data breach SC Staff July 27, 2026 Bleeping Computer reports that the parcel delivery company OnTrac has experienced a data breach, potentially exposing customer personal details following a cyberattack on its corporate network. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Basic Authentication Biometrics Corruption Covert Channels Darknet Deepfake Denial of Service Digest Authentication Password Authentication Protocol (PAP) You can skip this ad in 5 seconds

Share this article