Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities SecurityWeek

Password Managers Vulnerable to Vault Compromise Under Malicious Server

  • What: Researchers found vulnerabilities in password managers that could allow malicious servers to compromise user vaults.
  • Impact: Attackers could potentially access sensitive user data stored in Bitwarden, LastPass, Dashlane, and 1Password.
Read Full Article →

DATA PROTECTION Password Managers Vulnerable to Vault Compromise Under Malicious Server Researchers at ETH Zurich have tested the security of Bitwarden, LastPass, Dashlane, and 1Password password managers. By Eduard Kovacs | February 17, 2026 (4:30 AM ET) Flipboard Reddit Whatsapp Email A team of security researchers from ETH Zurich in Switzerland has analyzed popular password managers and identified ways in which threat actors could compromise users’ vaults and access sensitive data. However, the researchers did not test the password managers against external or client-side attacks. Instead they targeted zero-knowledge encryption, a security model where the service provider is unable to access the user’s encrypted data and the data should be protected even if the provider’s servers are compromised. As such, the ETH Zurich researchers conducted an analysis of popular cloud-based password managers under the assumption that the servers storing user vaults are “fully malicious”. The researchers targeted password managers from Bitwarden, Dashlane, LastPass, and 1Password, each having millions of users and overall accounting for a significant share of the market. Although 1Password was included in the research, the analysis focused on the other password managers. Several types of attacks were conducted against each of the tested password managers to degrade security guarantees, undermine expected protections, and fully compromise user accounts. The experts targeted features used for account recovery and SSO login, as well as features designed for backward compatibility. They conducted attacks leveraging improper vault integrity and attacks enabled by sharing features, which allow families or businesses to use the same credentials. ADVERTISEMENT. SCROLL TO CONTINUE READING. For each of the tested password managers, the researchers managed to achieve vault compromise, including full vault compromise for Bitwarden and LastPass, and shared vault compromise for Dashlane. They demonstrated that in many cases an attacker could not only view users’ credentials but also modify them. Password managers respond Some of the vendors pointed out that the attack methods identified by the researchers require full compromise of a password manager’s servers and advanced skills to conduct cryptographic attacks. Dashlane told SecurityWeek that some of the findings require “either specific circumstances and/or an extremely significant window of time”. The vendors have been notified and rolled out patches and mitigations for many of the vulnerabilities, but pointed out that some issues are difficult to address. “When users share items, symmetric keys are encrypted with the recipient’s public keys. As with most server‑mediated end-to-end encrypted (E2EE) systems, this creates a structural dependency on the authenticity of the public key directory,” Dashlane’s Frederic Rivain explained in a blog post. “If an attacker were able to substitute the user’s public key with their own, the attacker could gain access to the contents of shared items encrypted with the malicious public key.” Rivain added, “This is a known, industry‑wide challenge.” Bitwarden noted that of the 10 issues reported by the researchers — each rated as having medium or low impact — seven have been or are in the process of being addressed. However, three of the flaws “have been accepted as intentional design decisions necessary for product functionality”. LastPass told SecurityWeek that it appreciates the research but also suggested that it disagrees with some of the researchers’ assessments. “While our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zurich team, we take all reported security findings seriously. We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk,” a spokesperson stated. [ Read: LastPass Users Targeted With Backup-Themed Phishing Emails ] 1Password has also been analyzed and the researchers managed to achieve full compromise of vault confidentiality and integrity, allowing an attacker to obtain passwords and other sensitive data stored in the vault, as well as to add items to the vault. However, Jacob DePriest, CISO and CIO of 1Password, told SecurityWeek that the attack vectors identified by the researchers had already been documented in the company’s publicly available Security Design White Paper. “We are committed to continually strengthening our security architecture and evaluating it against advanced threat models, including malicious-server scenarios like those described in the research, and evolving it over time to maintain the protections our users rely on,” DePriest said. He added, “For example, 1Password uses Secure Remote Password (SRP) to authenticate users without transmitting encryption keys to our servers, helping mitigate entire classes of server-side attacks. More recently, we introduced a new capability for enterprise-managed credentials, which from the start are created and secured to withstand sophisticated threats.” Related: Password Managers Vulnerable to Data Theft via Clickjacking Related: Analysis of 6 Billion Passwords Shows Stagnant User Behavior WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat BeyondTrust Vulnerability Targeted by Hackers Within 24 Hours of PoC Release China Revives Tianfu Cup Hacking Contest Under Increased Secrecy Hacktivists, State Actors, Cybercriminals Target Global Defense Industry, Google Warns Conduent Breach Hits Volvo Group: Nearly 17,000 Employees’ Data Exposed Chipmaker Patch Tuesday: Over 80 Vulnerabilities Addressed by Intel and AMD Google-Intel Security Audit Reveals Severe TDX Vulnerability Allowing Full Compromise ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, Phoenix Contact Latest News Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security CISA Navigates DHS Shutdown With Reduced Staff Microsoft Warns of ClickFix Attack Abusing DNS Lookups Amazon Scraps Partnership With Surveillance Company After Super Bowl Ad Backlash Google Patches First Actively Exploited Chrome Zero-Day of 2026 Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data In Other News: Google Looks at AI Abuse, Trump Pauses China Bans, Disney’s $2.7M Fine TRENDING Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Robert Carvajal has been appointed as CISO of BayCare Health System. KnowBe4 announced the appointment of Kelly Morgan as Chief Customer Officer. CrowdStrike has named Jonathon Dixon as vice president and managing director for the JAPAC region. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article