Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers
ID: ef6a87ee-f046-54b0-adbe-a23668b0752f
STIX ID: report--ef6a87ee-f046-54b0-adbe-a23668b0752f
Feed Name: The Hacker News
A research study from ETH Zurich and Università della Svizzera italiana reveals numerous weaknesses in cloud-based password managers — 12 attacks against Bitwarden, 7 against LastPass, and 6 against Dashlane — that can lead to password recovery, integrity violations, and organizational vault compromise. The issues fall into four categories (key escrow/account recovery flaws, item-level encryption and metadata/authentication weaknesses, sharing-feature abuses, and legacy-compatibility downgrade attacks), affect services used by ~60 million users and ~125,000 businesses, and have prompted vendor mitigations; researchers report no evidence of exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
