Bitwarden makes it harder to hack password vaults without MFA
ID: 38370986-fe1a-54ff-994d-a4c9093f1372
STIX ID: report--38370986-fe1a-54ff-994d-a4c9093f1372
Feed Name: Bleeping Computer
Bitwarden is adding an email verification step for accounts that have not enabled two-factor authentication, requiring a one-time code when logging in from unrecognized devices; triggers include new devices, app reinstalls, and cleared browser cookies. Users who enable any 2FA method, use API keys or SSO, or operate self-hosted instances are exempt. Bitwarden advises users who store email credentials in their vaults to ensure independent email access or enable 2FA, and reminds all users to maintain strong, unique master passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
