logo

RSA SecureID software token update

ID: a09dc0d9-3031-58c7-b3c4-2195032703fa

STIX ID: report--a09dc0d9-3031-58c7-b3c4-2195032703fa

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2012-05-24

Date Updated: 2026-04-29

...
...

SensePost research describes two design weaknesses in RSA SecurID software tokens: (1) a token-binding bypass that allows an attacker who obtains a user’s token configuration file and initial password to import and use the token elsewhere, and (2) the broader issue that software tokens storing secret seeds on general-purpose OS/storage can be cloned or stolen (via DPAPI replication or API hooking). The report explains exploitation methods, discusses smartphone differences, and recommends hardware-backed or trusted-execution protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.