Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

25 Vulnerabilities Found in Cloud Password Managers, Exposing Users to Unauthorized Access and Changes

Recent research conducted by the Applied Cryptography Group at ETH Zurich has uncovered critical security vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. Together, these platforms serve approximately 60…

Recent research conducted by the Applied Cryptography Group at ETH Zurich has uncovered critical security vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. Together, these platforms serve approximately 60 million users. The study challenges the prevailing industry assumption that providers cannot access user data, even in the event of server compromise.

The researchers, led by Professor Kenneth Paterson, operated under a "malicious server threat model." They simulated a compromised service provider to evaluate how client applications, such as web browser extensions, would respond to unexpected server behavior.

The study identified a total of 25 distinct attack vectors:

Bitwarden: 12 vulnerabilities LastPass: 7 vulnerabilities Dashlane: 6 vulnerabilities

These vulnerabilities enable unauthorized access and modification of user vaults, ranging from targeted integrity violations to complete compromise within an organization. A significant cause of these issues is the complexity of the code required to support user-friendly features.

The study challenges the prevailing industry assumption that providers cannot access user data, even in the event of server compromise.
Zachary Burns · Thehackingpost

Target Vendor Vulnerabilities Detected Impact Type Threat Model

Bitwarden 12 Vault Access & Modification Malicious Server

LastPass 7 Vault Access & Modification Malicious Server

Dashlane 6 Vault Access & Modification Malicious Server

Advertisement

The vulnerabilities identified have significant implications for the "zero-knowledge" security model, which posits that data is encrypted on the device before reaching the cloud. The research demonstrated that a sophisticated hacker with server access could manipulate data streams to decrypt sensitive information.

Following standard responsible disclosure protocols, the researchers informed the affected vendors and provided a 90-day remediation period before publishing their findings. Although cooperative, vendors varied in their speed and willingness to implement fixes.

Recommendations for users include selecting password managers that undergo external audits and provide transparency regarding their security architecture. Additionally, vendors are encouraged to offer a migration path to modern cryptographic systems rather than continually patching legacy code.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories