logo

Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords

ID: 029e6df1-2041-5f8d-962c-73d493e1838d

STIX ID: report--029e6df1-2041-5f8d-962c-73d493e1838d

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

...
...

Researchers from ETH Zurich and USI published a peer-reviewed paper detailing 27 attack scenarios against cloud-based password managers (Bitwarden, LastPass, Dashlane, 1Password) that exploit cryptographic and design weaknesses—such as unauthenticated public keys, lack of ciphertext integrity, and KDF downgrades—to enable password and vault compromise; vendors were notified and are remediating the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.