Password managers keep your passwords safe, unless…
ID: 93cc86f6-0ae4-5100-94fd-61804f5b315c
STIX ID: report--93cc86f6-0ae4-5100-94fd-61804f5b315c
Feed Name: Malwarebytes Blog
Researchers demonstrated that cloud-based password managers' design and legacy compatibility choices—shared group keys, server-controlled recovery policies, downgradeable KDF iterations, and support for non‑AEAD modes—could allow a compromised or malicious server to recover vault keys and plaintext in targeted attacks; while attacks require a high level of compromise and many issues have been patched, users and organizations should enable MFA, avoid legacy clients/features, and apply vendor mitigations promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
