N-able Bug Exposes Password Vault Master Keys
ID: 2b386387-5e8d-5608-8de0-8ffe804675ab
STIX ID: report--2b386387-5e8d-5608-8de0-8ffe804675ab
Feed Name: Dark Reading
Threat Score
A researcher discovered that the Passportal browser extension trusted window.postMessage calls from any website or iframe, allowing malicious sites to obtain access and refresh tokens that enable theft of all stored credentials and TOTPs from customer vaults; N-able patched the extension to verify request origin, but the product still decrypts data server-side (no E2EE), raising ongoing supply-chain and large-scale compromise concerns for MSPs and their downstream clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
