Security News

Top 5 tips for using password managers
2021-09-29 12:42

Password managers are a good way to keep your passwords unique, strong and safe. A password manager is still the best way that balances convenience and security-with a heavy tilt toward security.

Zoho ManageEngine Password Manager Zero-Day Gets a Fix, Amid Attacks
2021-09-09 12:58

A critical security vulnerability in the Zoho ManageEngine ADSelfService Plus platform could allow remote attackers to bypass authentication and have free rein across users' Active Directory and cloud accounts. The Zoho ManageEngine ADSelfService Plus is a self-service password management and single sign-on solution for AD and cloud apps, meaning that any cyberattacker able to take control of the platform would have multiple pivot points into both mission-critical apps and other parts of the corporate network via AD. It is, in other words, a powerful, highly privileged application which can act as a convenient point-of-entry to areas deep inside an enterprise's footprint for both users and attackers alike.

Kaspersky Password Manager Generated Passwords That Could Quickly Be Brute-Forced
2021-07-07 14:37

A vulnerability in the Kaspersky Password Manager resulted in the created passwords being weak enough to allow an attacker to brute-force them in seconds, a security researcher claims. Developed by Russian security firm Kaspersky, the Kaspersky Password Manager allows users not only to securely store passwords and documents, but also to generate passwords when needed.

Kaspersky Password Manager's random password generator was about as random as your wall clock
2021-07-06 20:49

Last year, Kaspersky Password Manager users got an alert telling them to update their weaker passwords. Three months later, a team from security consultancy Donjon found that KPM didn't manage either task particularly well - the software used a pseudo-random number generator that was insufficiently random to create strong passwords.

Vulnerability in the Kaspersky Password Manager
2021-07-06 14:27

The password generator included in Kaspersky Password Manager had several problems. All the passwords it created could be bruteforced in seconds.

1Password: How to install the password manager on Linux
2021-05-19 15:11

Jack Wallen installed 1Password on Linux and found it to be a fantastic solution for password management. Follow his tutorial on how to get this proprietary solution installed on your open source OS. This is a tricky proposition for some-an official 1Password client has been released for Linux.

Passwordstate Password Manager Update Hijacked to Install Backdoor on Thousands of PCs
2021-04-26 00:33

Click Studios, the Australian software company behind the Passwordstate password management application, has notified customers to reset their passwords following a supply chain attack. "Manual Upgrades of Passwordstate are not compromised. Affected customers password records may have been harvested."

Passwordstate password manager hacked in supply chain attack
2021-04-23 20:18

Click Studios, the company behind the Passwordstate enterprise password manager, notified customers that attackers compromised the app's update mechanism to deliver malware in a supply-chain attack after breaching its networks. Passwordstate is an on-premises password management solution used by over 370,000 security and IT professionals at 29,000 companies worldwide, as the company claims.

Free password manager alternatives to LastPass
2021-02-22 14:07

With the free version of LastPass now limiting where you can sync your passwords, here are a few other options. LastPass has typically gotten kudos as an effective password manager.

LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month
2021-02-16 23:27

The free version of LastPass - which people use to store passwords, notes, credit card details and so on - currently works across devices; a single login will give you access to all the associated data. From March 16, users will be required to choose which "Active device type" they want to use for the free service.