The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

A recently disclosed vulnerability in N-able's Passportal password manager reportedly exposed master keys for password vaults. The flaw, which affects a product widely used by Managed Service Providers (MSPs) and Small and Medium Businesses (SMBs), raises concerns about the security of cloud-based password management solutions even after a patch has been applied.
The core issue appears to stem from the architecture of Passportal, particularly its cloud-based design. While a patch has been released, the summary indicates that the product may still present risks. This suggests that the vulnerability might not have been a simple coding error but potentially related to how sensitive cryptographic material, like master keys, is handled or stored within a cloud environment, or how the patch interacts with existing cloud deployments.
In many password managers, a master key is the ultimate credential that unlocks access to all other stored passwords. Its compromise would grant an attacker full access to all credentials managed by the affected vault. For MSPs, this could mean exposure of client credentials, while for SMBs, it could lead to a widespread compromise of internal systems and data.
This class of vulnerability often involves improper key management, insecure storage of cryptographic keys, or flaws in the authentication and authorization mechanisms that protect access to these keys. Cloud-based systems introduce additional complexities, such as securing multi-tenant environments, protecting data in transit and at rest across distributed infrastructure, and ensuring the integrity of cloud service provider components.
Typical mitigation guidance for such issues generally includes immediate application of vendor-supplied patches, robust access controls for administrative interfaces, and strict adherence to the principle of least privilege. Organizations using cloud-based solutions are also advised to implement strong multi-factor authentication, regularly audit access logs, and consider the implications of their cloud provider's security posture and data handling practices.
The report prompts a broader discussion about the suitability of cloud environments for highly sensitive applications like password managers. While cloud solutions offer scalability and accessibility, they also centralize data, making them attractive targets for attackers. The question posed is whether such products should avoid cloud deployment entirely, or if current cloud security paradigms are insufficient for the unique risks associated with master key management.
This incident underscores the ongoing challenge of securing critical infrastructure components, especially those that manage access to other systems. As organizations increasingly rely on third-party and cloud-based services for fundamental security functions, the architectural decisions and security implementations of these vendors become paramount to the overall cybersecurity posture of their customers.

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.