Shared Security: Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass

Tom Eston, Scott Wright, Kevin Johnson Tom Eston, Scott Wright, Kevin Johnson 2/6/23 - Episode Page

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.



Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.



A bug in Meta's Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.