Search/dashlane
Vendor

dashlane

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
dashlane
Connections
18 relationships
Product showcase: Dashlane Password Manager is more security toolkit than password vault
Product showcase: Dashlane Password Manager is more security toolkit than password vault Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web monitoring and phishing protection. The service is available on Windows, macOS, Linux (web app), Android, iPhone and iPad, with browser extensions for Chrome, Edge, Firefox, Safari and other Chromium-based browsers. Passwords, passkeys and other vault items sync across supported devices. Getting started The iOS app guides you through account creation with either a master password or a passwordless setup. During testing, the passwordless option used Face ID, a device PIN and a recovery key instead of requiring a master password from the start. The app prompts users to save the recovery key as a PDF for offline storage before completing the setup. Organising your vault The vault is organised into categories including logins, secure notes, payment cards, personal information, IDs and Wi-Fi credentials, making it easy to separate different types of data. Adding new items is straightforward, and the search bar provides quick access once the vault grows. A built-in password generator lets you adjust password length and character types before copying the generated password for new accounts. Password Health checks stored credentials for weak, reused or compromised passwords, while Dark Web Monitoring alerts users if monitored email addresses appear in known breaches. Both features are available from the Tools section alongside the authenticator, sharing and device connection options. The mobile app includes a For You tab that serves as a setup checklist, covering tasks such as importing passwords, enabling autofill and checking for compromised credentials. It also displays subscription information and security notifications. Pricing and final thoughts New accounts include a 14-day Premium trial, unlocking features such as VPN access, password sharing and additional security capabilities. At the end of the trial, it’s possible to subscribe to a paid plan or export stored passwords. Dashlane combines password management with account security tools in a single application. Passwordless onboarding, the password generator, password health reports, dark web monitoring and mobile autofill are all accessible from the main interface, making it a practical choice for managing credentials across smartphones, tablets, desktops and web browsers.
helpnetsecurity.comJul 30, 2026extracted
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. The project is the OWASP reference implementation for ASI06, Memory Poisoning, one entry in the OWASP Top 10 for Agentic Applications. Data discovery gaps that catch enterprises off guard In this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, post-merger surprises where duplicated datasets slowed integration, and why synthetic data is overmarketed while confidential computing stays underappreciated. Zero trust physical security needs trust decisions at the edge In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. A small Slovenian team handles 6,000 cyber incidents a year Online fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen analysts sorts through them. Gorazd Božič, who manages SI-CERT at the public agency ARNES, described that work in an interview conducted in person at the Span Cyber Security Arena conference. He put the original proposal for a Slovenian CERT to ARNES leadership in 1994, and the center now records about 6,000 incidents a year, up from roughly 300 ten to fifteen years earlier. Only 11% of production agents pass the AI agent security bar Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the conditions for a single hostile document to take them over. Spotless compliance evidence can still hide a broken control In this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss the 320 assessment objectives beneath them, why spotless SOC 2 evidence can hide a broken control, and how continuous monitoring is changing compliance work. OAuth marketplace apps keep access after publishers vanish Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth grants behind them often reach into business systems beyond the listed function. Thieves can pull off keyless car theft in under a minute and here’s how to stop them A keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. The vulnerability runs across the global market. Germany’s largest auto club, ADAC, runs ongoing tests of keyless models against relay attacks. AgentGG: Open-source agentic SAST scanner Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. The good news, though, is that the company hasn’t observed any indication of successful lateral movement from the devices. How NIST fumbled management of the National Vulnerability Database A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD). Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned last Friday. CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment. Google fixes actively exploited Android vulnerability (CVE-2025-48595) Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” Autonomous AI-driven worm can reason its way through corporate networks Researchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, reasons about how to attack it, and creates a strategy on the fly, all with the help of a small, free large language model (LLM) running directly on machines it has already compromised. Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. June 2026 Patch Tuesday forecast: Where are the CVEs? Forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The modern-day business can learn a lot about risk from this year’s mega events Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now anticipation is building for the fast-approaching FIFA World Cup. But amid the buzz, have you ever paused to consider the staggering level of risk inherent to such large-scale events? Or how impressive it is that organizers are able to manage that risk so successfully? From critical to controlled: Cutting vulnerabilities in a live manufacturing environment A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the ticket and call it a day. If, however, you’re in OT or dealing with ICS in a live manufacturing facility, it’s rarely that simple. Why you need BAS and autonomous pentesting together A new autonomous penetration testing tool delivers impressive results at first—finding critical issues, uncovering undocumented attack paths, and exposing forgotten accounts. But by the fourth or fifth run, the discoveries dry up. The tool keeps reporting the same stale issues, and the dashboard becomes another source of noise. What seemed like continuous validation quietly turns into a repeat of the same well-worn attack paths. Governing shadow AI without killing innovation In this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also need to do it safely. What CISOs need to do about post-quantum migration in the next 24 months In this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organizations about two and a half years to prepare. AI agent governance gets harder when agents outnumber your people In this Help Net Security video, Amit Gautam, CTO at Abluva, explains the security risks that autonomous AI agents bring into enterprise environments. EU organizations buckle under rising compliance pressure Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Compliance Department Manager at Span, spoke with Help Net Security at the Span Cyber Security Arena conference about how these regulatory frameworks are shaping compliance priorities and day-to-day decision-making. DNS-AID lets AI agents find and verify each other through DNS AI agents run across many platforms, and each one needs a way to locate and confirm the identity of the others it works with. The Linux Foundation’s DNS-AID project gives them that capability through the Domain Name System, the same address lookup system that has directed internet traffic for decades. The project lets AI agents and Model Context Protocol (MCP) servers use DNS as a global, vendor-neutral directory for publishing, discovering, and verifying one another. Brute-force attack triggers Dashlane account lockouts Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. Meta tries to get ahead of scammers before the World Cup begins Football fans are counting down the days until the FIFA World Cup begins, and scammers are doing the same. Last week, the FBI warned that cybercriminals are spoofing FIFA websites to steal personal information, sell fake tickets, and promote fraudulent hospitality packages ahead of the tournament. Sensitive government personnel data posted online, Spanish police arrest suspect The Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. 64,000 accounts exposed in breach of GTA V cheat service Atlas Menu Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of thousands of user records. The incident exposed approximately 64,000 accounts, including email addresses, usernames, IP addresses, support tickets, and passwords hashed with bcrypt. Anthropic expands Project Glasswing to 150 organizations in more than 15 countries Anthropic is expanding Project Glasswing, its cybersecurity initiative built around the Claude Mythos Preview model, by adding about 150 organizations following several weeks of work with its initial group of partners, security firms, open-source maintainers, and government agencies. Malware campaign targeting Minecraft users infects over 116,000 systems A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found. Microsoft responds to security challenges facing code, AI agents, and models Microsoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabilities, and tools designed to identify potentially vulnerable or compromised AI models before deployment. AI is helping low-skill hackers pull off advanced cyberattacks Anthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026. The company mapped the observed behavior to the MITRE ATT&CK framework, which documents tactics and techniques used by attackers. Attackers obtained encrypted password vaults from some Dashlane user accounts Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. 145 AI laws passed in 2025 and privacy teams aren’t catching a break 145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. NVIDIA goes open source with a big batch of physical AI agent tools NVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, vision AI, and industrial digital twins, and break it into bite-sized tasks that AI agents can actually run themselves. Microsoft Defender Vulnerability Management gets a smarter exposure score Microsoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public preview. This AI model backdoor attack stays hidden until you customize the model Most teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of the model. A research team built an attack called BadBone. It plants a backdoor inside a backbone model. Downstream tasks that adapt the model inherit the backdoor. The name points at the target. Corrupt the skeleton, and systems built on top of it carry the flaw. OpenAI brings frontier AI to existing AWS environments OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. These capabilities are available through OpenAI models on Amazon Bedrock, a platform for building generative AI applications and agents at production scale. The platform enables teams to build AI applications using AWS-native security and governance controls. KDE Linux security audit cuts kernel modules and unused packages KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel during the prior month. Codex knowledge work expands into research, reports, and spreadsheets Office workers in the United States lose hours each week to email triage and to searching for files spread across disconnected systems. Roughly 40 percent of US labor, about 72 million people, works primarily with information such as analysis, documents, designs, and communication. Research from the McKinsey Global Institute puts the average knowledge worker at 28 percent of the workweek on email and close to 20 percent on hunts for internal information or for colleagues who can help with specific tasks. Meta adds stricter guardrails for teen feeds Meta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter restrictions. Meta plans to roll out the feature on Facebook and Messenger later this year. Known vulnerabilities behind most application security incidents Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condition across the industry, where the window between identifying a flaw and closing it in production stays open long enough for attackers to act. Agent Threat Rules: Open detection rule format for AI agent security threats AI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the tooling built to catch them. Agent Threat Rules, or ATR, is an open detection format aimed at this category of attack. Microsoft Scout agent opens a new category of always-on Autopilots Workplace AI assistants have mostly waited for a prompt before doing anything. A user asks, the tool answers, and the exchange ends there. Microsoft is putting a different kind of agent inside its Office applications, one designed to keep operating in the background once a person stops paying attention. The company introduced Microsoft Scout, calling it the first entry in a category it labels Autopilots. New Android feature promises to spot deepfake scam calls Android is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. ETSI sets security requirements for AI data centers and cloud platforms ETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for platforms used to host AI applications in data center and edge computing environments, covering security functions, platform components, interfaces, and services designed to protect AI models, datasets, training processes, and inference workloads. Product showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websites Trend Micro Mobile Security for iOS protects devices from potentially harmful websites while browsing, blocks ads and personal information trackers, helps users avoid unsafe Wi-Fi networks, and monitors data usage. The app is available for both iOS and Android devices. Most pros have seen AI hallucinations in IT operations Autonomous AI is taking action inside enterprise IT environments. Software is restarting services, isolating risky devices, and applying patches without waiting for a human to approve the step. The capability is spreading at the same time IT professionals are reporting frequent encounters with AI output errors that can carry operational impact. Let’s Encrypt works toward post-quantum certificates at web scale Let’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a staging environment that issues MTCs, with a production-ready environment planned for 2027. Photos: Infosecurity Europe 2026 Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here’s a closer look at the conference. Attackers already know the secrets are on your developers’ machines. Do you? In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) added another 22%. Simplify security management with CIS SecureSuite Platform CIS SecureSuite Membership simplifies the process with tools, benefits, and resources for implementing the secure recommendations of the CIS Benchmarks. With the release of CIS SecureSuite Platform, it’s now even easier for Members to harden their systems. Cybersecurity jobs available right now: June 2, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 5, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma.
helpnetsecurity.comJun 7, 2026extracted
Attackers obtained encrypted password vaults from some Dashlane user accounts
Attackers obtained encrypted password vaults from some Dashlane user accounts Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. “Your account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn’t enter the correct token after several tries,” the emails read, instructing affected users to contact customer support to restore access. Shortly after, Dashlane launched an investigation into reports from users who had received account suspension notifications and were experiencing difficulties logging in after resetting their master password. According to Dashlane, the threat actor targeted API endpoints used for device registration and launched a high volume of automated requests in an attempt to gain access to user accounts. The company said its automated security systems responded by locking targeted accounts to protect affected users. “Before the attack was fully mitigated, the threat actor was able to brute force and generate valid tokens for fewer than 20 personal plan customers, allowing them to register a new device on those accounts and download copies of users’ encrypted vaults,” Dashlane stated. The advisory notes that the copied vaults remain encrypted and require the user’s master password to unlock. However, stolen vaults can still be subjected to offline password-cracking attempts, making the strength of a user’s master password a key factor in limiting the risk of exposure. Following the incident, Dashlane said it deployed additional protections at the network and product levels to detect and filter malicious traffic. The company is also adding verification steps to the device registration process. The company’s handling of the outage drew criticism on Reddit, where some users complained that Dashlane had provided little information while the issue was unfolding. Earlier this year, researchers at ETH Zurich and the Università della Svizzera italiana identified design weaknesses in several major password managers, including Dashlane. While unrelated to the recent brute-force attack, the researchers demonstrated scenarios in which a compromise of a provider’s infrastructure could expose or modify data stored in encrypted vaults. The risks associated with stolen password vaults can also persist long after an incident. TRM Labs warned that encrypted vault backups stolen during the 2022 LastPass breach were still being cracked using weak master passwords, enabling cryptocurrency thefts as late as 2025.
helpnetsecurity.comJun 5, 2026extracted
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads
Password management and credential security solutions provider Dashlane revealed on Monday that it has been targeted in a brute-force attack campaign that resulted in a limited number of encrypted vaults being downloaded by the attackers. According to Dashlane, the attack began on May 31, with attackers attempting to brute-force 2FA to register their own devices on targeted accounts. The hackers, the company said, used automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived security code expires”. Registering a device gives the attacker the access required to download the targeted user’s encrypted vault from Dashlane servers. The attack was quickly detected and the targeted accounts were automatically locked to limit impact. However, Dashlane said the attackers did manage to compromise some accounts. The threat actor downloaded a copy of the encrypted vaults belonging to fewer than 20 personal plan users. “Dashlane vault data cannot be accessed without the Master Password, and our vault encryption ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time,” Dashlane said. The company noted that the only way for an attacker to obtain a user’s master password is through phishing. The locked accounts have since been restored and affected users have been notified. “There is no evidence that Dashlane’s internal system has been impacted,” Dashlane said. Related: Carnival Data Breach Exposed 6 Million People Related: Charter Communications Data Breach Could Impact Nearly 5 Million
securityweek.comJun 2, 2026extracted
Dashlane password manager users locked out by brute force attacks
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. In a statement to BleepingComputer, the password management service confirmed that the suspensions were part of an automated security response designed to protect against account hijacking. “We can confirm that certain Dashlane user accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane’s built-in security controls. The affected accounts have now been unsuspended,” stated Jordan Fylolenko, Dashlane Senior Director of Corporate Communications. “Our team is actively engaged in this issue and taking measures to further protect customers. There is no evidence of compromise of Dashlane’s systems.” Worried Dashlane users reported earlier today on Reddit that they received notices of suspicious access requests from foreign countries. The emails contained verification codes for legitimate account owners to register new devices. Many users were confused because they had not initiated the requests and tried to confirm if the communication was part of a phishing attempt targeting Dashlane users. A few hours later, Dashlane responded to some of these Reddit threads, saying that its systems were safe and the action was triggered by brute-force attacks, which seek to gain access to an account by trying multiple passwords in succession until the correct one is found. Secure platforms implement protection measures such as rate limiting, CAPTCHA challenges, and account lockouts to block automated attacks after a threshold of failed attempts is reached. According to Dashlane’s status page, an investigation into the incident was launched on May 31 at 15:19 UTC, and by 22:30 UTC, the issue was marked as ‘RESOLVED,’ claiming that all affected accounts had been unsuspended. Another update issued on June 1 at 07:32 UTC confirmed the same status, with Dashlane assuring that its team was monitoring the situation and was implementing additional targeted measures. Despite the platform flagging the issue as resolved, some users continue to report login problems, mentioning that support is unresponsive. BleepingComputer has asked Dashlane additional questions about the incident to determine the number of impacted accounts, but the company has not provided a response as of publication. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 1, 2026extracted
Brute-force attack triggers Dashlane account lockouts
Brute-force attack triggers Dashlane account lockouts Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. “Your account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn’t enter the correct token after several tries,” the emails stated, instructing affected users to contact customer support to restore access. Shortly after, Dashlane said it was investigating reports from users who had received account suspension notifications and were experiencing difficulties logging in after resetting their master passwords. In a follow-up update, Dashlane said its engineering teams were investigating the root cause of the account suspension notifications and working on a resolution while treating the incident as a high-priority issue. Later that day, the company confirmed that certain user accounts had been targeted in a brute-force attack by an external party, triggering automatic account suspensions as part of Dashlane’s built-in security measures. According to Dashlane’s status page, the incident affected the company’s email notification and 2FA systems. “Our team is actively engaged in this issue and taking measures to address it. There is no evidence of compromise of Dashlane’s systems,” the company said. Although Dashlane marked the incident as resolved on May 31, it changed the status to “monitoring” on June 1. The company’s handling of the outage drew criticism on Reddit, where some users complained that Dashlane had provided little information while the issue was unfolding. Others said they were unsure whether the account suspension emails were legitimate because they arrived before Dashlane publicly explained what was happening. Dashlane later responded on Reddit, reassuring users and repeating that there was no evidence its systems had been compromised.
helpnetsecurity.comJun 1, 2026extracted
Password manager Dashlane suspends customer accounts amid brute-force attacks
SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comJun 1, 2026extracted
Top product launches at RSAC 2026
Top product launches at RSAC 2026 RSAC 2026 showcased a wave of innovation, with vendors unveiling technologies poised to redefine cybersecurity. From AI-powered defense to breakthroughs in identity protection, this year’s conference delivered a glimpse into the future. Here are the most interesting products that caught our attention, and could shape what’s next. Astrix Security has revealed a major expansion of its AI agent security platform, covering every layer where AI agents operate in the enterprise: from managed AI platforms to shadow deployments running on managed devices, detecting both agent existence and unauthorized access to enterprise resources, and enforcing policy over what agents are allowed to do. Bonfy.AI announced Bonfy Adaptive Content Security (Bonfy ACS) 2.0, a platform built to secure enterprise content across all systems, applications, and AI agents – anywhere data moves, resides, or is processed. Bonfy delivers real-time, contextual protection across email, SaaS apps, collaboration tools, browsers, cloud and on‑prem file stores, AI systems, and agent frameworks, so enterprises can safely accelerate AI adoption without flying blind. The Vellox suite showcases how AI-native cyber defense can counter growing threats to U.S. national security and critical infrastructure. The product suite is fueled by more than 30 years of technology, tradecraft, and adversarial insights. Booz Allen’s cyber operators are engaged at the center of nearly all major commercial and federal cyber missions, enabling singular insight when developing and deploying military-grade offensive and defensive products for U.S. federal, defense, and intelligence customers as well as Fortune 500 and Forbes Global 2000 companies. Black Duck has announced the general availability of Black Duck Signal, an agentic AI application security solution purpose-built to secure AI-generated code in autonomous development workflows. Signal introduces a new model for application security: agentic AI augmented by decades of human-curated security context. Delivered as an agentic AI solution, Signal enlists a coordinated system of specialized AI security agents that draw on ContextAI, Black Duck’s application security model, to analyze code, assess impact and guide remediation actions in real time. Cisco has introduced solutions to address AI security issues and remove a top barrier to agent adoption. By establishing trusted identities, enforcing strict zero trust Access controls, hardening agents before deployment, enforcing guardrails at runtime, and giving SOC teams the tools to stop threats at machine speed, Cisco is building security into the foundation of the emerging AI economy. Mimecast has announced a major expansion of its Incydr offering with new data security capabilities and a preview of the Agent Risk Center. These enhancements deliver runtime data security through a unified approach to detect, govern, and remediate data exposure in real time, whether driven by employees or agents acting on their behalf. Novee introduced AI Red Teaming for LLM Applications for its AI penetration testing platform, designed to uncover security vulnerabilities in LLM-powered applications before attackers can exploit them. Unlike conventional application security tools built for web and infrastructure testing, Novee’s AI pentesting agent is specifically designed to continuously probe AI-enabled applications. The agent autonomously simulates real-world, sophisticated attack scenarios and chaining techniques together to identify vulnerabilities that manual testing or static scanners often miss. Dashlane has unveiled Omnix AI Advisor, a natural-language AI security assistant embedded into the Dashlane Omnix platform. Built upon Omnix’s advanced credential protection and visibility capabilities, Omnix AI Advisor accelerates enterprises’ transition to a proactive security posture by turning real-time credential risk data, such as dark web exposure and phishing logs, into contextual, actionable intelligence. Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. Prisma AIRS replaces fragmented point solutions with a single platform to manage the primary threats and risks of AI apps and autonomous agents. The new capabilities allow teams to future-proof their operations as agent ecosystems evolve. Stellar Cyber has introduced agentic AI to cut alert noise and speed investigations, changing how SOC teams operate. The enhancements advance its autonomous SOC platform, shifting teams from reactive alert handling to outcome-driven security operations. Straiker has launched Discover AI and expanded Defend AI to secure coding agents, productivity agents, and custom-built agent platforms. Agents are operating across enterprise systems with broad access, growing autonomy, and zero security oversight. That’s why Straiker built Discover AI and Defend AI: to give security teams visibility into what agents are running and protection against what they might do. Teleport announced Beams, a trusted runtime designed to solve the security and IAM challenges blocking teams from designing and running AI agents in production infrastructure. Beams runs each agent in an isolated Firecracker VM with built-in identity. Each Beam is connected to infrastructure and inference services without secrets, with audit and access control.
helpnetsecurity.comMar 26, 2026extracted
New Torg Grabber infostealer malware targets 728 crypto wallets
A new info-stealing malware called Torg Grabber is stealing sensitive data from 850 browser extensions, more than 700 of them for cryptocurrency wallets. Initial access is obtained through the ClickFix technique by hijacking the clipboard and tricking the user into executing a malicious PowerShell command. According to researchers at cybersecurity company Gen Digital, Torg Grabber is actively developed, with 334 unique samples compiled in three months (between December 2025 and February 2026) and new command-and-control (C2) servers registered every week. Apart from cryptocurrency wallets, Torg Grabber steals data from 103 password managers and two-factor authentication tools, and 19 note-taking apps. Rapid evolution In a technical report this week, Gen Digital researchers say that Torg Grabber's initial builds used a Telegram-based and then a custom, encrypted TCP protocol for data exfiltration. On December 18, 2025, the two mechanisms were abandoned in favor of an HTTPS connection routed through Cloudflare infrastructure. The method supports chunked data uploads and payload delivery. The malware features several anti-analysis mechanisms, multi-layered obfuscation, and uses direct syscalls and reflective loading for evasion, running the final payload entirely in memory. On December 22, 2025, Torg Grabber added App-Bound Encryption (ABE) bypass to beat Chrome’s (and Brave's, Edge's, Vivaldi's, and Opera's) cookie protection system, like many other information stealers. However, the researchers also discovered a standalone tool called Underground, used for extracting browser data. It injects a DLL reflectively into the browser to access Chrome’s COM Elevation Service and extract the master encryption key, a method also recently seen in VoidStealer. Extensive data theft capabilities Gen Digital found that Torg Grabber targets 25 Chromium-based browsers and 8 Firefox variants, trying to steal credentials, cookies, and autofill data. Of the 850 browser extensions it targets, 728 are for cryptocurrency wallets, covering "essentially every crypto wallet ever conceived by human optimism." "The marquee names are all there - MetaMask, Phantom, TrustWallet, Coinbase, Binance, Exodus, TronLink, Ronin, OKX, Keplr, Rabby, Sui, Solflare," the researchers say. "But the list doesn’t stop at the big names. It keeps going, deep into the long tail, past projects with install counts you could fit in a phone booth." Apart from wallets, the malware also targets a large list of 103 extensions for passwords, tokens, and authenticators: LastPass, 1Password, Bitwarden, KeePass, NordPass, Dashlane, ProtonPass, Enpass, Psono, Pleasant Password Server, heylogin, 2FAAuth, GAuth, TOTP Authenticator, and Akamai MFA. Torg Grabber also targets information from Discord, Telegram, Steam, VPN apps, FTP apps, email clients, password managers, and desktop cryptocurrency wallet apps. The malware can also profile the host, create a hardware fingerprint, document installed software (including 24 antivirus tools), take screenshots of the user’s desktop, and steal files from the Desktop/Documents folders. Also notable is its capability to execute shellcode on the compromised device, delivered in ChaCha-encrypted zlib-compressed form from the C2. Gen Digital cautions that Torg Grabber continues to develop rapidly, registering new C2 domains weekly, and that its operator base is expanding, with 40 tags documented by the time of analysis. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 25, 2026extracted
Password manager, tra promesse di inattaccabilità e lacune nella sicurezza
Se c’è una promessa che il marketing dei password manager ha trasformato in un mantra, è quella della zero-knowledge encryption: “i vostri dati sono cifrati end-to-end, nemmeno noi sappiamo cosa custodite nel vault”. Una garanzia che ha convinto milioni di utenti e migliaia di aziende ad affidare a questi servizi cloud le credenziali più critiche, tra cui accessi a sistemi bancari, piattaforme aziendali e infrastrutture IT. Lo scorso 16 febbraio 2026, l’Applied Cryptography Group del Politecnico federale di Zurigo (ETH Zurich)[1] ha pubblicato una ricerca che sta scuotendo il settore. Il paper “Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers”[2] verrà presentato alla conferenza USENIX Security 2026 e rappresenta il primo studio sistematico sull’architettura crittografica dei principali password manager cloud-based[3]. Il titolo gioca volutamente con le parole: zero knowledge non indica solo la promessa commerciale, ma la reale conoscenza (o meglio: la mancanza di essa) che i fornitori dimostrano circa la sicurezza dei loro stessi sistemi. “Il punto non è se i password manager sono inutili, ma che il marketing della zero-knowledge li ha venduti come cassaforte inviolabile e l’ETH Zurich gli ha appena tolto il lucchetto davanti a tutti”, sottolinea Sandro Sana, Ethical Hacker e membro del Comitato Scientifico Cyber 4.0. Giorgio Sbaraglia, consulente aziendale cyber security e membro del Comitato Direttivo Clusit, aggiunge anche altre importanti considerazioni: “La scoperta delle vulnerabilità nel modello zero-knowledge che è alla base del funzionamento dei password manager è certamente preoccupante, ma vanno fatte alcune considerazioni”. “Non esiste un sistema sicuro al 100%, cioè qualunque sistema è vulnerabile”, continua Giorgio Sbaraglia, “ma è importante valutare almeno questi aspetti: Quanto è effettivamente sfruttabile la vulnerabilità? E quali sono le alternative? In altre parole: non tutti i password manager sono sicuri allo stesso livello, ma rimangono comunque – oggi – il miglior compromesso tra sicurezza e praticità. Almeno fino a quando continueremo ad utilizzare le password come sistema di autenticazione”. Indice degli argomenti Per comprendere la portata della ricerca è necessario capire il modello di attacco adottato dai ricercatori. In particolare, il team di ricerca ha simulato uno scenario in cui un server del password manager risulta compromesso e stiamo parlando di una condizione non solo teorica, considerato che LastPass ha subito una violazione significativa dei propri sistemi nel 2022 che ha portato alla compromissione di dati cifrati degli utenti. Il presupposto è il cosiddetto malicious server threat model: in pratica, il server è in mano a un attaccante che può deviare arbitrariamente dal comportamento atteso e interagire in modo malevolo con i client degli utenti (browser extension, app mobile, client desktop). I ricercatori hanno quindi configurato server propri che si comportavano come versioni compromesse dei password manager originali. La cosa sorprendente e preoccupante è che non sono stati necessari exploit sofisticati: gli attacchi sfruttano interazioni di routine come il semplice login all’account, l’apertura del vault, la visualizzazione di una password o la sincronizzazione dei dati tra dispositivi, azioni che ogni utente compie più volte al giorno. “Se il threat model ‘server compromesso’ produce 25 attacchi concreti su Bitwarden, LastPass e Dashlane, allora la promessa “anche noi non possiamo leggere nulla” non basta più come garanzia: serve integrità oltre alla cifratura”, è il punto su cui richiama l’attenzione Sandro Sana. Invece, riprendendo le sue considerazioni iniziali, Giorgio Sbaraglia aggiunge che: “La domanda “quanto è effettivamente sfruttabile la vulnerabilità?” rappresenta un discrimine sostanziale per comprendere la gravità del problema”. “Il team di ricercatori di ETH Zurich ha simulato uno scenario in cui un server del password manager risulta compromesso: questa è una condizione possibile (e già accaduta con LastPass), ma comunque non semplice da ottenere da parte dell’attaccante”, fa notare giustamente Sbaraglia, aggiungendo che: “La compromissione del server è il requisito per lo sfruttamento delle vulnerabilità scoperte: non si tratta quindi di exploit eseguibili da remoto, quindi non così semplici da realizzare”. Integrity violations: modifica silenziosa di specifiche voci nel vault di un utente target Full vault compromise: accesso completo a tutte le credenziali di un’organizzazione Credential substitution: sostituzione di URL associati a una password (phishing facilitato) Key recovery attacks: recupero della chiave master in particolari condizioni di sincronizzazione Share/recovery feature abuse: sfruttamento delle funzioni di condivisione e recupero account “Siamo rimasti sorpresi dalla gravità delle vulnerabilità”, ha dichiarato il professor Kenneth Paterson, titolare della cattedra di Computer Science all’ETH Zurich. Una sorpresa che ha una spiegazione precisa: i password manager sono tra i pochi servizi cloud che promettono cifratura end-to-end e ci si aspettava che proprio per questa ragione il loro codice fosse sottoposto a un livello di scrutinio crittografico superiore alla media. Ma, evidentemente, così non è stato. La causa principale identificata dai ricercatori è una tensione strutturale tra usabilità e sicurezza. Le aziende sviluppatrici investono molto nell’aggiungere funzionalità che rendono il servizio più comodo: recupero dell’account in caso di perdita della master password, condivisione del vault con familiari o colleghi, sincronizzazione multi-dispositivo, piani Enterprise con gestione centralizzata degli accessi. Ciascuna di queste funzionalità introduce nuovi flussi crittografici, nuove interazioni tra client e server, nuovi percorsi di codice che espandono la superficie d’attacco. “Il codice diventa più complesso e confuso, e amplia i potenziali vettori per gli hacker”, spiega Matteo Scarlata, dottorando dell’Applied Cryptography Group che ha condotto parte degli attacchi. Un ulteriore problema è l’inerzia tecnologica: molti provider continuano a usare primitive crittografiche degli anni ’90, obsolete secondo gli standard attuali, con la motivazione dichiarata che gli aggiornamenti possano impedire ai clienti di accedere ai propri dati. Un timore comprensibile perché perdere l’accesso a migliaia di credenziali aziendali sarebbe catastrofico, ma che non può giustificare indefinitamente l’uso di crittografia vulnerabile. I ricercatori hanno ovviamente seguito il processo di responsible disclosure contattando i tre provider 90 giorni prima della pubblicazione dei risultati della loro ricerca. Bitwarden, LastPass e Dashlane hanno risposto in modo cooperativo, ma con tempi di remediation diversi e non tutte le vulnerabilità risultano corrette al momento della pubblicazione della ricerca. Tutti i dettagli tecnici sono disponibili nel paper di ricerca, di seguito riportiamo una sintesi sui dati più importanti: Bitwarden, 12 vulnerabilità. Bitwarden, il più popolare tra i password manager open source e molto diffuso in ambito Enterprise grazie alla sua opzione self-hosted, presenta il maggior numero di vulnerabilità documentate: 12. La nature open source del codice non ha impedito queste falle, a dimostrazione che la trasparenza del codice non è sufficiente senza un’analisi crittografica formale sistematica. LastPass, 7 vulnerabilità. LastPass si conferma ancora una volta sotto i riflettori negativi. I 7 attacchi documentati includono scenari di compromissione completa del vault. Il precedente storico rende questa notizia particolarmente significativa per le organizzazioni che non hanno ancora migrato a soluzioni alternative. Dashlane, 6 vulnerabilità. Spesso considerato il password manager più orientato alla sicurezza tra i tre, presenta 6 vulnerabilità. Meno degli altri, ma sufficiente a dimostrare che nessun provider analizzato può attualmente garantire le promesse di sicurezza assoluta presenti nei propri materiali di marketing. Prima di cedere al panico e di cancellare in massa gli account sui password manager è necessario inquadrare correttamente la portata della ricerca. Le vulnerabilità documentate richiedono che un attaccante abbia già compromesso i server del provider. Non si tratta di exploit eseguibili da remoto senza accesso all’infrastruttura, né di falle nel client locale. Questo, tuttavia, non riduce la gravità del problema per due ragioni fondamentali. Innanzitutto, gli attacchi ai server di password manager sono già avvenuti (LastPass 2022 docet) e rappresentano target ad alto valore per gruppi APT e criminali organizzati. La seconda ragione è la promessa zero-knowledge su cui si basa l’intera proposta di valore di questi servizi e che presuppone che anche un server compromesso non metta a rischio i dati degli utenti. Questa promessa è ora formalmente falsificata. La conclusione di Sandro Sana è perentoria: “Per le aziende la morale è semplice: le credenziali privilegiate non stanno in un vault cloud “perché è comodo”, stanno sotto PAM/controlli dedicati e con segmentazione seria. I password manager restano utili, ma da oggi vanno trattati come infrastruttura critica, non come app da smartphone con la password Master123!”. Il professor Paterson raccomanda di scegliere un password manager che sia trasparente riguardo alle vulnerabilità, sottoposto ad audit esterni regolari e con la cifratura end-to-end abilitata per impostazione predefinita. Di seguito riportiamo anche alcuni criteri concreti per orientare la scelta: Preferire provider che pubblicano regolarmente report di audit di terze parti (es. Cure53, NCC Group, Trail of Bits). Verificare che la cifratura E2E sia attiva di default, non come funzionalità opzionale. Valutare soluzioni self-hosted (es. Bitwarden self-hosted, Vaultwarden) se avete le competenze tecniche per gestirle: eliminano il vettore “server compromesso dal provider”. Abilitare l’autenticazione a più fattori (MFA) sul vault: non risolve le vulnerabilità strutturali, ma riduce significativamente il rischio di accesso non autorizzato. Utilizzare master password robuste e uniche, ossia non riutilizzate altrove. Audit dell’inventario: censire tutti i password manager in uso (sia approvati che shadow IT). Classificazione del rischio: le credenziali di sistemi critici (directory, firewall, cloud IAM) non dovrebbero essere esclusivamente protette da password manager cloud-based senza controlli aggiuntivi. Segmentazione delle credenziali: usare soluzioni enterprise on-premise o PAM (Privileged Access Management) per le credenziali privilegiate, riservando i password manager cloud agli accessi meno sensibili. Formazione: comunicare internamente la notizia evitando allarmismo eccessivo, ma sensibilizzando sulla natura reale delle garanzie offerte dai vendor. Monitoring: implementare alerting su accessi anomali ai vault aziendali. Inventariate quali password manager cloud-based sono in uso nella vostra organizzazione. Verificate se tra i provider in uso figurano Bitwarden (cloud), LastPass o Dashlane. Valutate se avete abilitato funzionalità di sharing, family/team plan o recovery account: queste aumentano la superficie d’attacco. Richiedete ai vendor una comunicazione ufficiale sulle patch rilasciate in risposta alla ricerca ETH. Considerare un audit crittografico formale del password manager aziendale se trattate dati critici o regolamentati (NIS2, GDPR, settore bancario/sanitario). Il team ETH non si è limitato a documentare le vulnerabilità, ma ha fornito indicazioni concrete per migliorare la sicurezza del settore. La proposta centrale di Scarlata è pragmatica: aggiornare gradualmente i sistemi per i nuovi clienti secondo gli standard crittografici più recenti, in particolare l’adozione di schemi autenticati e resistenti alla manipolazione come AEAD (Authenticated Encryption with Associated Data) in modalità binding robuste. È importante, inoltre, abbandonare le primitive crittografiche legacy degli anni ’90. Per i clienti esistenti, la proposta è offrire una migrazione volontaria al nuovo sistema, con piena trasparenza sulle vulnerabilità del sistema attuale. Un approccio che rispetta sia le esigenze di continuità del servizio sia il diritto degli utenti di fare scelte informate. “Vogliamo che il nostro lavoro contribuisca a cambiare questo settore”, ha dichiarato Paterson. “I provider di password manager non dovrebbero fare false promesse ai propri clienti riguardo alla sicurezza, ma comunicare in modo più chiaro e preciso quali garanzie le loro soluzioni offrono davvero.” È un principio che va ben oltre i password manager: si applica a qualsiasi prodotto di sicurezza che fa marketing basato su garanzie crittografiche. Trasparenza, audit indipendenti e standard aggiornati non sono optional: sono precondizioni per la fiducia. Ci sono altre due considerazioni importanti da fare a commento di questa notizia. La prima è che i password manager non sono tutti uguali: ce ne sono molte decine reperibili sugli store, ma alcuni sono migliori di altri. Avendo personalmente testato molti password manager ritengo che 1Password sia uno dei migliori (come interfaccia e funzionalità) ma soprattutto uno dei più sicuri. E anche lo studio condotto da ETH Zurich lo conferma: 1Password nei loro test ha dimostrato una resistenza maggiore rispetto ai suoi concorrenti. Ciò è dovuto in gran parte all’uso di una “chiave segreta” ad alta entropia combinata con la password principale dell’utente durante la crittografia. 1Password combina infatti la sicurezza della funzione PBKDF2 con l’uso della chiave segreta (Secret Key). Questa offre una protezione aggiuntiva e più forte qualora i server di 1Password dovessero essere violati. La Secret Key, lunga oltre 30 caratteri, viene creata nel browser o nel client 1Password sul computer dell’utente quando questi crea il suo account 1Password. Tutto ciò avviene interamente sul computer dell’utente e non viene inviato ai server di 1Password, che quindi non conosce la Secret Key. Questo ulteriore livello di sicurezza aumenta significativamente la resistenza agli attacchi di forza bruta, con i ricercatori che osservano che tali attacchi sarebbero “fuori portata” in condizioni normali. La seconda considerazione è più generale: l’autenticazione con password è comunque intrinsecamente debole: come ha ribadito il NIST nel suo recente documento SP 800-63-4 la password non è un’autenticazione resistente al phishing. Quindi dobbiamo andare verso soluzioni diverse dalla password, che peraltro già esistono: per esempio le Passkeys. È un progetto presentato da Apple, Google e Microsoft sotto l’egida della Fido Alliance oltre tre anni fa, nel maggio 2022. Passkeys rappresenta una soluzione di autenticazione sicura e “passwordless”, basata sulla biometria e sulla crittografia asimmetrica. Ma nella mia attività di consulente aziendale constato che il tasso di adozione di questa soluzione è ancora molto basso e fatica a crescere. Esiste, quindi, un problema culturale di fondo – e a tutti i livelli – sull’uso dei sistemi di autenticazione e sulla consapevolezza della loro importanza. Giorgio Sbaraglia I password manager rimangono strumenti preziosi e, per la maggior parte degli utenti, rappresentano un significativo miglioramento rispetto all’alternativa di usare password deboli o riutilizzate. Nulla in questa ricerca suggerisce di abbandonarli in massa. Quello che cambia – e che deve cambiare – è il contesto di fiducia. Le promesse di sicurezza assoluta, di zero-knowledge totale, di “nemmeno noi possiamo accedere ai vostri dati” devono essere sostituite da comunicazioni più oneste, audit pubblici regolari e aggiornamenti crittografici sistematici. Come professionisti della sicurezza, dobbiamo dunque trasmettere ai nostri clienti e stakeholder un messaggio equilibrato: i password manager sono strumenti con un profilo di rischio specifico, come qualsiasi altro strumento. Comprenderlo ci rende più sicuri, non meno. [1] ETH Zurich: “Password managers less secure than promised”. [2] Scarlata M, Torrisi G, Backendal M, Paterson K: “Zero Knowledge (About) Encryption” — USENIX Security 2026, preprint.
cybersecurity360.itFeb 25, 2026extracted
Design weaknesses in major password managers enable vault attacks, researchers say
Design weaknesses in major password managers enable vault attacks, researchers say Can cloud-based password managers that claim “zero-knowledge encryption” keep users’ passwords safe even if their encrypted-vault servers are compromised? Researchers at ETH Zurich and Università della Svizzera italiana set out to answer that question, and the answer is (unfortunately) no. Attack paths against encrypted vaults Cloud-based password managers store users’s passwords in a password vault, which is created and encrypted by the user’s client software by using a cryptographic key derived from the user’s master password. The client software uploads the encrypted vault to a server run by the service provider and the provider can’t decrypt it. Only the user’s client software can: it retrieves the vault and uses the user’s master password to decrypt it locally (i.e., on the user’s device). But, as the researchers demonstrated, attackers who manage to compromise a server that stores the password vaults can, in some cases, recover users’ passwords, fully compromise the vault, modify its contents, and more. The researchers probed four popular password managers: Bitwarden, LastPass, Dashlane, and 1Password. They presented 12 distinct attack scenarios against Bitwarden, 7 against LastPass, 6 against Dashlane, and 3 against 1Password. The attacks are grouped in four categories, depending on the password manager feature they exploit: Key escrow (used for vault recovery, in case the user forgets their master password, or for account recovery), Item-level vault encryption (data items in the vault and user settings are encrypted as separate objects, and often combined with unencrypted or unauthenticated metadata) Credential sharing Backwards compatibility (to support older software client versions) Across these categories, they found that design weaknesses – such as missing key authentication, lack of authenticated encryption, poor key separation, and legacy cryptographic support – can allow attackers who tamper with server-stored data to manipulate keys, metadata, or ciphertext. In many cases, these flaws can lead to severe outcomes such as full vault compromise, loss of confidentiality, or loss of integrity. Importantly, several attacks require little or no user interaction (sometimes just a login or sync) and affect multiple products studied. “We were surprised by the severity of the security vulnerabilities,” said Prof. Dr. Kenneth Paterson, from the Applied Cryptography Group at ETH Zurich. “Since end-to-end encryption is still relatively new in commercial services, it seems that no one had ever examined it in detail before.” (Some) fixes are available The researchers proposed a set of changes that can be implemented to mitigate all of these attacks, but noted vendors’ reluctance to introduce changes that would break functionality or, at worst, lead to irretrievable loss of access to vaults/passwords. “To this aim, we propose the use of specialized password manager clients, with no functionality besides implementing a forced migration to the new vault format. This would prevent any user from losing access to their data, while preserving security for the entire user base,” the researchers advised. The four affected vendors were appraised of the research many months before it was made public. They have since moved to fix some of these exploitable design flaws, while pointing out that others – like the verification of public key authenticity – are industry‑wide challenges that are yet to be successfuly solved. While they all pointed out that this research was valuable to help them keep their users safe, they noted that they have found no indication that any of these attacks have been successfully leveraged to compromise their customers. The researchers themselves noted that while most users are unlikely to be targeted via the attacks they presented, as they require considerable skills and knowledge from the attackers, but higher risk individuals and organizations might be. “Unfortunately, we cannot exclude the possibility that our attacks were already known to advanced threat actors – after all, we have learned from the Snowden revelations that national security agencies are routinely tasked with penetrating systems like the ones we analyse and are willing to conduct active attacks on targets,” they said. “The best mitigation for these parties is to trust that vendors will rapidly and effectively patch their systems, and here we have made real effort to engage with the affected vendors to assist them in this process.” UPDATE (February 17, 2026, 02:00 p.m. ET): “Our security team reviewed the paper in depth and found no new attack vectors beyond those already documented in our publicly available Security Design White Paper,” 1Password’s CISO/CIO Jacob DePriest told Help Net Security. “We are committed to continually strengthening our security architecture and evaluating it against advanced threat models, including malicious-server scenarios like those described in the research, and evolving it over time to maintain the protections our users rely on,” he added. “For example, 1Password uses Secure Remote Password (SRP) to authenticate users without transmitting encryption keys to our servers, helping mitigate entire classes of server-side attacks. More recently, we introduced a new capability for enterprise-managed credentials, which from the start are created and secured to withstand sophisticated threats.” Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comFeb 17, 2026extracted
Password Managers Vulnerable to Vault Compromise Under Malicious Server
A team of security researchers from ETH Zurich in Switzerland has analyzed popular password managers and identified ways in which threat actors could compromise users’ vaults and access sensitive data. However, the researchers did not test the password managers against external or client-side attacks. Instead they targeted zero-knowledge encryption, a security model where the service provider is unable to access the user’s encrypted data and the data should be protected even if the provider’s servers are compromised. As such, the ETH Zurich researchers conducted an analysis of popular cloud-based password managers under the assumption that the servers storing user vaults are “fully malicious”. The researchers targeted password managers from Bitwarden, Dashlane, LastPass, and 1Password, each having millions of users and overall accounting for a significant share of the market. Although 1Password was included in the research, the analysis focused on the other password managers. Several types of attacks were conducted against each of the tested password managers to degrade security guarantees, undermine expected protections, and fully compromise user accounts. The experts targeted features used for account recovery and SSO login, as well as features designed for backward compatibility. They conducted attacks leveraging improper vault integrity and attacks enabled by sharing features, which allow families or businesses to use the same credentials. For each of the tested password managers, the researchers managed to achieve vault compromise, including full vault compromise for Bitwarden and LastPass, and shared vault compromise for Dashlane. They demonstrated that in many cases an attacker could not only view users’ credentials but also modify them. Password managers respond Some of the vendors pointed out that the attack methods identified by the researchers require full compromise of a password manager’s servers and advanced skills to conduct cryptographic attacks. Dashlane told SecurityWeek that some of the findings require “either specific circumstances and/or an extremely significant window of time”. The vendors have been notified and rolled out patches and mitigations for many of the vulnerabilities, but pointed out that some issues are difficult to address. “When users share items, symmetric keys are encrypted with the recipient’s public keys. As with most server‑mediated end-to-end encrypted (E2EE) systems, this creates a structural dependency on the authenticity of the public key directory,” Dashlane’s Frederic Rivain explained in a blog post. “If an attacker were able to substitute the user’s public key with their own, the attacker could gain access to the contents of shared items encrypted with the malicious public key.” Rivain added, “This is a known, industry‑wide challenge.” Bitwarden noted that of the 10 issues reported by the researchers — each rated as having medium or low impact — seven have been or are in the process of being addressed. However, three of the flaws “have been accepted as intentional design decisions necessary for product functionality”. LastPass told SecurityWeek that it appreciates the research but also suggested that it disagrees with some of the researchers’ assessments. “While our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zurich team, we take all reported security findings seriously. We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk,” a spokesperson stated. [ Read: LastPass Users Targeted With Backup-Themed Phishing Emails ] 1Password has also been analyzed and the researchers managed to achieve full compromise of vault confidentiality and integrity, allowing an attacker to obtain passwords and other sensitive data stored in the vault, as well as to add items to the vault. However, Jacob DePriest, CISO and CIO of 1Password, told SecurityWeek that the attack vectors identified by the researchers had already been documented in the company’s publicly available Security Design White Paper. “We are committed to continually strengthening our security architecture and evaluating it against advanced threat models, including malicious-server scenarios like those described in the research, and evolving it over time to maintain the protections our users rely on,” DePriest said. He added, “For example, 1Password uses Secure Remote Password (SRP) to authenticate users without transmitting encryption keys to our servers, helping mitigate entire classes of server-side attacks. More recently, we introduced a new capability for enterprise-managed credentials, which from the start are created and secured to withstand sophisticated threats.” Related: Password Managers Vulnerable to Data Theft via Clickjacking Related: Analysis of 6 Billion Passwords Shows Stagnant User Behavior
securityweek.comFeb 17, 2026extracted
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers
A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditions. "The attacks range in severity from integrity violations to the complete compromise of all vaults in an organization," researchers Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, and Kenneth G. Paterson said. "The majority of the attacks allow the recovery of passwords." It's worth noting that the threat model, per the study from ETH Zurich and Università della Svizzera italiana, supposes a malicious server and aims to examine the password manager's zero-knowledge encryption (ZKE) promises made by the three solutions. ZKE is a cryptographic technique that allows one party to prove knowledge of a secret to another party without actually revealing the secret itself. ZKE is also a little different from end-to-end encryption (E2EE). While E2EE refers to a method of securing data in transit, ZKE is mainly about storing data in an encrypted format such that only the person with the key can access that information. Password manager vendors are known to implement ZKE to "enhance" user privacy and security by ensuring that the vault data cannot be tampered with. However, the latest research has uncovered 12 distinct attacks against Bitwarden, seven against LastPass, and six against Dashlane, ranging from integrity violations of targeted user vaults to a total compromise of all the vaults associated with an organization. Collectively, these password management solutions serve over 60 million users and nearly 125,000 businesses. "Despite vendors' attempts to achieve security in this setting, we uncover several common design anti-patterns and cryptographic misconceptions that resulted in vulnerabilities," the researchers said in an accompanying paper. The attacks fall under four broad categories - Attacks that exploit the "Key Escrow" account recovery mechanism to compromise the confidentiality guarantees of Bitwarden and LastPass, resulting from vulnerabilities in their key escrow designs. Attacks that exploit flawed item-level encryption -- i.e., encrypting data items and sensitive user settings as separate objects and often combine with unencrypted or unauthenticated metadata, to result in integrity violations, metadata leakage, field swapping, and key derivation function (KDF) downgrade. Attacks that exploit sharing features to compromise vault integrity and confidentiality. Attacks that exploit backwards compatibility with legacy code that result in downgrade attacks in Bitwarden and Dashlane. The study also found that 1Password, another popular password manager, is vulnerable to both item-level vault encryption and sharing attacks. However, 1Password has opted to treat them as arising from already known architectural limitations. When reached for comment, Jacob DePriest, Chief Information Security Officer and Chief Information Officer at 1Password, told The Hacker News that the company's security reviewed the paper in detail and found no new attack vectors beyond those already documented in its publicly available Security Design White Paper. "We are committed to continually strengthening our security architecture and evaluating it against advanced threat models, including malicious-server scenarios like those described in the research, and evolving it over time to maintain the protections our users rely on," DePriest added. "For example, 1Password uses Secure Remote Password (SRP) to authenticate users without transmitting encryption keys to our servers, helping mitigate entire classes of server-side attacks. More recently, we introduced a new capability for enterprise-managed credentials, which from the start are created and secured to withstand sophisticated threats." As for the rest, Bitwarden, Dashlane, and LastPass have all implemented countermeasures to mitigate the risks highlighted in the research, with LastPass also planning to harden its admin password reset and sharing workflows to counter the threat posed by a malicious intermediary. There is no evidence that any of these issues has been exploited in the wild. Specifically, Dashlane has patched an issue where a successful compromise of its servers could have allowed a downgrade of the encryption model used to generate encryption keys and protect user vaults. The issue was fixed by removing support for legacy cryptography methods with Dashlane Extension version 6.2544.1 released in November 2025. "This downgrade could result in the compromise of a weak or easily guessable Master Password, and the compromise of individual 'downgraded' vault items," Dashlane said. "This issue was the result of the allowed use of legacy cryptography. This legacy cryptography was supported by Dashlane in certain cases for backwards compatibility and migration flexibility." Bitwarden said all identified issues are being addressed. "Seven of which have been resolved or are in active remediation by the Bitwarden team," it said. "The remaining three issues have been accepted as intentional design decisions necessary for product functionality." In a similar advisory, LastPass said it's "actively working to add stronger integrity guarantees to better cryptographically bind items, fields, and metadata, thereby helping to maintain integrity assurance."
thehackernews.comFeb 16, 2026extracted
Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords
A group of academic security researchers have detailed a set of vulnerabilities in four popular cloud-based password managers that could allow an attacker to view and change the passwords stored in a victim’s vaults. The researchers, from ETH Zurich and the Università della Svizzera italiana (USI), in Switzerland, developed 27 successful attack scenarios targeting cloud-based password management services from Bitwarden, LastPass, Dashlane and 1Password. The attacks ranged in severity from integrity violations to the complete compromise of all vaults in an organization, with many of these scenarios allowing attackers to recover passwords. These attack scenarios challenged the password management providers’ claims of offering ‘zero-knowledge encryption,’ which conveys the idea that the server storing the user vaults cannot learn anything about its contents, even if it is compromised. The findings were published in a peer-reviewed paper released on February 16 and will be the subject of a talk at the next USENIX Security Symposium, which will be held in Baltimore, MD in August 2026. Attacking End-to-End Encryption Claims The 27 attack scenarios developed by the researchers revealed common design anti-patterns and cryptographic misconceptions, including unauthenticated public keys, lack of ciphertext integrity, insufficient key separation and missing cryptographic binding between data and metadata. They fell into four categories based on the password manager feature they exploited: Key escrow: full vault compromise via unauthenticated key escrow and account recovery features (four successful attacks: three against Bitwarden, one against LastPass) Vault encryption: integrity violations, metadata leakage, field swapping and key derivation function (KDF) downgrade through flawed item-level encryption (11 successful attacks: five against LastPass, four against Bitwarden, one against Dashlane and one against 1Password) Sharing: organization and shared vault compromise via unauthenticated public keys (five successful attacks: two against Bitwarden, one against LastPass, one against Dashlane, one against 1Password) Backwards compatibility: downgrade to insecure legacy encryption, enabling confidentiality loss and brute-force attacks (seven successful attacks: four against Dashlane, three against Bitwarden) In total, the researchers presented 12 distinct attack scenarios against Bitwarden, seven against LastPass, six against Dashlane and two against 1Password. They noted that, unlike the other three password managers, 1Password includes a high-entropy cryptographic key in the key derivation – which the company calls a “secret key” – alongside the master password a user needs to access its vaults and passwords. This grants 1Password with a security advantage and means “brute-force attacks should be out of reach,” the researchers added. Kenneth Paterson, professor at ETH Zurich’s Department of Computer Science and one of the lead authors of the paper, said that he and his colleagues were “surprised by the severity of the security vulnerabilities.” He explained that his team had already discovered similar vulnerabilities in other cloud-based services but had assumed a significantly higher standard of security for password managers due to the critical data they store. “Since end-to-end encryption is still relatively new in commercial services, it seems that no one had ever examined it in detail before,” he said. Malicious Auto-Enrolment Against Bitwarden An example of an attack developed by the researchers was a ‘malicious auto-enrolment’ attack against a cloud-based Bitwarden vault (BW01). This exploited a critical flaw in Bitwarden’s organization onboarding process, where an adversary controlling the server could silently hijack a user’s vault the moment they accepted an invitation, even from a trusted source. The core issue was in the lack of integrity protection for organization data fetched during onboarding, including policies and cryptographic keys. When a user joins an organization, their client blindly trusts the server’s response, allowing an attacker to manipulate it. By enabling auto-enrolment in the account recovery policy and swapping the organization’s legitimate public key with their own, an attacker could force the client to encrypt the user’s master key under the malicious key, handing it over without resistance. The attack unfolds in three key steps. The adversary intercepts the user’s request to join the organization, replacing the server’s response with a tampered policy (setting auto-enrolment to true) and a forged public key The client, unaware of the deception, encrypts the user’s master key under the attacker’s key and sends it back as an ‘account recovery ciphertext’ Finally, the attacker decrypts this ciphertext using their private key, exposing the master key With the user’s master key in hand, the attacker could gain full access to all stored passwords, notes, and sensitive data, as well as the ability to modify or delete entries undetected. The impact can be severe: a single compromised server can lead to the mass compromise of users, even if they join legitimate, trusted organizations. Worse, the attack scales exponentially. If an attacker breaches one user in an organization, they gain access to the organisation’s private key, which could be shared among several members of their team. Remediation Underway at Bitwarden, LastPass and Dashlane The researchers disclosed their findings to Bitwarden, LastPass and Dashlane through a coordinated 90-day disclosure process that included detailed descriptions of all vulnerabilities. They also offered support through video conferences, email exchanges and patch review. All three vendors notified the researchers that remediation of these vulnerabilities is underway. 1Password, also made aware of the two attack scenarios performed by the researchers against their services, did not request an embargo period but said the company regards the vulnerabilities as “arising from already known architectural limitations.” Jacob DePriest, CISO/CIO at 1Password told Infosecurity that the firm's security team reviewed the paper in depth and found no new attack vectors beyond those already documented in their publicly available Security Design White Paper. He also explained that 1Password regularly evaluates the company's security architecture against advanced threat models, including malicious-server scenarios like those described in the research, and evolve it when needed. "For example, 1Password uses secure remote password (SRP) to authenticate users without transmitting encryption keys to our servers, helping mitigate entire classes of server-side attacks. More recently, we introduced a new capability for enterprise-managed credentials, which from the start are created and secured to withstand sophisticated threats," DePriest added. Dashlane shared a blog post addressing the paper’s findings and detailing a fix the firm deployed to mitigate the issue. LastPass said the company was "grateful" for the research. "While our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zurich team, we take all reported security findings seriously," a LastPass spokesperson told Infosecurity. "We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk.” The ETH Zurich researchers noted that they have “no reason to believe” that the password manager vendors are currently malicious or compromised and that passwords “are safe as long as things stay that way.” “That said, password managers are high-value targets, and breaches do happen,” the researchers added. Additionally, a Dashlane spokesperson told Infosecurity it found no evidence of exploitation related to these issues. Mitigation Recommendations In the scientific paper, the researchers said their attacks can all be mitigated using a combination of authentication methods, such as authentication encryption, key separation, plaintext authentication, public key authentication and ciphertext authentication. Users of Bitwarden, LastPass or Dashlane are advised to check the remediation status of their providers. Users of other password managers can see if their passwords could be compromised by similar attacks by asking their providers to commission an audit or asking the following questions: Do you offer end-to-end encryption? What security do you provide in case your server infrastructure was to be compromised? How do you check that public keys and public-key ciphertexts are authentic? How do you authenticate security-critical settings, such as the KDF type and the iteration count? Do you provide integrity guarantees for a user's vault as a whole? Can a malicious server add items to your vault? The article was updated on February 17 to add comments from 1Password and Dashlane and on February 18 to add comments from LastPass.
infosecurity-magazine.comFeb 16, 2026extracted
Phishing scam uses fake death notices to trick LastPass users
LastPass has alerted users about a new phishing attack that claims the recipient has died. According to the message, a family member has submitted a death certificate to gain access to the recipient’s password vault. A link in the phishing email, supposedly to stop the request, leads to a fake page that asks for the LastPass user’s master password. “Legacy Request Opened (URGENT IF YOU ARE NOT DECEASED) A death certificate was uploaded by a family member to regain access to the Lastpass account If you have not passed away and you believe this is a mistake, please reply to this email with STOP” LastPass links this campaign to CryptoChameleon (also known as UNC5356), a group that previously targeted cryptocurrency users and platforms with similar social engineering attacks. The same group used LastPass branding in a phishing kit in April 2024. The phishing attempt exploits the legitimate inheritance process, which is an emergency access feature in LastPass that allows designated contacts request access to a vault if the account holder dies or becomes incapacitated. Stealing someone’s password manager credentials gives attackers access to every login stored inside. We recently reported on an attempt to steal 1Password credentials. Lastpass also notes that: “Several of the phishing sites are clearly intended to target passkeys, reflecting both the increased interest on the part of cybercriminals in passkeys and the increased adoption on the part of consumers.” Passkeys are a very secure replacement for passwords. They can’t be cracked, guessed or phished, and let you log in easily without having to type a password every time. Most password managers—like LastPass, 1Password, Dashlane, and Bitwarden—now store and sync passkeys across devices. Because passkeys often protect high-value assets like banking, crypto wallets, password managers, and company accounts—they’ve become an attractive prize for attackers. Advice for users While passkeys themselves cannot be phished via simple credential theft, attackers can trick users into: Registering a new passkey on a malicious site or a fake login page Approving fraudulent device syncs or account transfers Disabling passkeys and reverting to weaker login methods, then stealing those fallback credentials LastPass and other security experts recommend: Never enter your master password on links received via email or text. Understand how passkeys work and keep them safe. Only logging into your password manager via official apps or bookmarks. Be wary of urgent or alarming messages demanding immediate action. Remember that legitimate companies won’t ask for sensitive credentials via email or phone. Use an up-to-date real-time anti-malware solution preferably with a web protection module. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comOct 27, 2025extracted
Life, death, and online identity: What happens to your online accounts after death?
Life, death, and online identity: What happens to your online accounts after death? The rapid technological advances of recent decades have transformed nearly every aspect of our lives. One major shift is that many of us now maintain extensive digital footprints, spanning countless online accounts, from email and social media to banking, investments, cloud storage, utility payments, and more. In life, we work hard to protect these accounts from others, particularly cybercriminals. Yet when death or incapacity strikes, ensuring that our loved ones have legal access to them becomes critically important. This emerging area of asset management remains in its early stages, facing a complex technological landscape, fragmented (or nonexistent) legal frameworks, and significant systemic gaps. To address these challenges, the OpenID Foundation (OIDF) has been developing a new whitepaper and a digital estate planning guide that examine this issue on a global scale. In this Help Net Security interview, Dean H. Saxe, an OpenID Foundation member and long-time contributor to digital identity standards, discusses this initiative and what the Foundation hopes to accomplish with them. (Dean H. Saxe’s answers have been edited for length and clarity.) Why did the OpenID Foundation decide to focus on the problem of what happens to digital assets after death, and why do you think this issue has been neglected for so long? I became interested in this idea in 2010, when a close friend of mine passed away unexpectedly at a young age, leaving behind his wife and two young children. We both worked in security and his data was difficult for his family to obtain after his passing. At the time, I considered how we could implement a dead man’s switch that would activate after a specified period of account inactivity. This could be used, for example, to release account credentials to a chosen loved one. However, the penetration of credential managers was very low at the time, so the idea was put on the back burner for years. In 2022, I was in Berlin for the European Identity & Cloud (EIC) Conference. The FIDO Alliance had just announced synced passkeys, a significant development that highlighted both a challenge and an opportunity. The challenge was that digital credentials, such as passkeys, would not allow an individual to write down their credentials, creating more barriers to accessing the digital estate of an individual after death. The opportunity, however, was the increased use of credential managers that would occur as passkeys became commonplace for most users. I shared my ideas with a select group of identity standards architects, including Vittorio Bertocci, a friend and mentor. They all agreed. Unfortunately, Vittorio got sick and passed away on October 7, 2023. In the following weeks I talked to members of the identity community at the Authenticate Conference and the Internet Identity Workshop. Each of these conversations helped move forward the ideas that eventually became the Death and the Digital Estate Community Group (DADE CG). The group was chartered in September 2024 and began to meet regularly in November 2024. As regards to why this issue has been neglected for so long, I cannot say for sure. However, many of my friends and colleagues are uncomfortable talking about death and thinking of their own mortality. I, too, am uncomfortable with the topic! I think that’s a natural barrier that has prevented us from making headway until now. What kind of problems do businesses encounter and what kinds of risks do companies face when employees or customers pass away without a clear digital estate plan? I first encountered this problem a while back in a previous role when a customer services team member came to me with the questions: “What do we do with the account and digital assets of a customer who has passed away? How do we verify they have died?” At the time, there weren’t any runbooks for how to handle the death of a customer. Once again, because many people are uncomfortable discussing death, we had not planned for it. In my own experience working with various organizations, it’s clear that we fail to consider what to do when our customers or users pass away or become incapacitated. And until we pave a clear path for organizations to follow, it is unlikely that we’ll see broad adoption of mechanisms for managing death and the disposition of users’ digital assets. I see two clear problems for companies today: First, how do you prove that a customer has died? Second, how do you ensure that the customer’s digital assets are handled in accordance with their wishes? In the first case, proving the death of a user will depend on the jurisdiction in which they died, so unique processes will have to be created depending on the jurisdiction. This is incredibly difficult and time consuming to manage on a worldwide basis. In the second, there is no clear pathway to establish who is responsible for the decedent’s digital assets and how they wish to have them handled. (Though Kudos to Apple, Google, Facebook, and other organizations that have established mechanisms that individuals can configure to establish a mechanism for their chosen legacy managers to handle their accounts in accordance with their wishes.) But we still lack a universal set of mechanisms that operate within the context of law and culture to manage a digital estate. Should some accounts be inheritable (e.g., accounts where you pay for games, books, etc., or accounts storing digital art and other creative digital works)? That is, should the contents be inheritable? I’m not a lawyer, so I don’t feel like this is an area I can weigh in upon. However, if these assets are inheritable, there must be a pathway to enable this inheritance which may, or may not, exist today. How is AI, and especially tools that generate content or simulate people’s voices and likenesses, making this issue more complex? This seems to me a completely novel problem – who has the “rights” to this “material”, and are companies already misusing the access they have to photos, videos and audio recordings? We’re in the early days of understanding how AI impacts death. There are tools that allow individuals to create AI avatars of themselves for their friends and family to “speak” with after death. This is behavior that the individual will have consented to. On the other hand, there are AI avatars created without the knowledge or consent of the deceased. In one famous case, a murdered man’s sister created an AI deepfake of her brother which was played in court during the sentencing phase for the person who murdered him. The images were of the deceased man, but the words he “spoke” were those of his sister. Is this right? Is this wrong? I can only speak for myself to say that this makes me incredibly uncomfortable. The current draft of the paper says that “digital estate planning will not be viable at scale until the technical stack supports delegation that is verifiable, revocable, interoperable, and usable by the average person with or without legal representation. Service providers, such as social media sites, cloud services, and online crypto wallets, require digital estate services to manage their users’ legacy managers.” Can you see this happening without regulations? What’s the incentive for service providers? Today, we lack the tools (protocols) and the regulations to enable digital estate management at scale. Law and regulation can force a change in behavior by large providers. However, lacking effective protocols to establish a mechanism to identify the decedent’s chosen individuals who will manage their digital estate, every service will have to design their own path. This creates an exceptional burden on individuals planning their digital estate, and on individuals who manage the digital estates of the deceased. For example, some services require the use of impersonation – logging in as the user with their credentials – to close their digital accounts. But impersonation can be abused. There have been many instances of deceased individuals “posting” new content on social media accounts after their death. The incentive for service providers to resolve these gaps is unclear to me. While I hope that they are incentivized by being good citizens of the world, this is unlikely to create the change we need. If laws don’t catch up quickly, do you think people will start treating their digital assets like “contraband”, e.g., secretly sharing passwords or creating shadow archives to bypass companies? Sharing of credentials is already happening and, in many cases, is a recommended practice due to a lack of other mechanisms for managing digital assets. What are the most important aspects that need to be addressed correctly to achieve satisfactory digital estate “handover”? I encourage you to review the planning guide we released for public comment alongside the white paper. However, to answer the question, I encourage individuals to document their digital estate: list every online account including social media, financial, insurance, healthcare, email, cloud file storage, etc., along with the username for the account. Ideally, all this information along with the user’s credentials (e.g. passwords, passkeys, and OTPs) are stored in a suitable credential manager, such as 1Password, BitWarden, or Dashlane. The data should include specific instructions, where relevant, regarding your wishes for handling of the data after you have passed away. For example, you may wish to have your Facebook account memorialized while your blog should be maintained for five years before being shut down and removed from the internet. The data is yours – take care to be explicit how you’d like it to be handled after your death. The individual should store the necessary data to unlock the credential manager in a secure place that can be accessed after their death. Depending on their circumstances, this may mean leaving the data with their lawyer or other estate planning professional. If the data is provided to a loved one, there is a risk of abuse of the trust they have placed in this individual. Finally, work with a lawyer familiar with estate planning and digital assets to ensure that your digital estate is properly represented in your estate documents, along with your specific wishes for each account and the data contained within the account. You’ve been involved in this project for a while. Were there any comments that surprised you? And were there aspects you hadn’t considered before starting the project? Absolutely! Early in the DADE work a member of the community group expressed discomfort with the word death. In their culture, it is considered impolite to use such terms. As an American growing up culturally Jewish, my view of death and related practices were influenced by what I observed in my own life. My co-author, Mike Kiser, did a masterful job of documenting some of the different belief systems and practices around the world that impact how individuals talk about, think about, and manage death. I’m glad to have a partner like Mike to help expand our understanding of the cultural and religious practices around death and dying to inform our work. If we are to be successful in developing protocols for managing digital estates, the protocols must be flexible enough to account for the different practices and laws found around the world. I look forward to learning more as we continue this work to ensure that all humans worldwide can manage their digital estates in a way that is culturally and religiously appropriate. What do you hope this white paper and guide will change, in terms of public awareness and industry standards? When we set out to write this paper, we wanted to influence the large technology and social media platforms, politicians, regulators, estate planners, and others who can help change the status quo. Further, we hoped to influence standards development organizations, such as the OpenID Foundation and the Internet Engineering Task Force (IETF), and their members. As standards developers in the realm of identity, we have an obligation to the people we serve to consider identity from birth to death and beyond, to ensure every human receives the respect they deserve in life and in death. Additionally, we wrote the planning guide to help individuals plan for their own digital estate. By giving people the tools to help describe, document, and manage their digital estates proactively, we can raise more awareness and provide tools to help protect individuals at one of the most vulnerable moments of their lives. The comment period for the paper and guide ends on Friday, October 24th. Instructions for how to send in comments can be found here. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comOct 22, 2025extracted