LIVE · cybersecurity feed
Live wire
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsCritical Elementor Pro bug exposes WordPress sites to RCE attacksThe push to designate AI as the next critical infrastructure sectorCritical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

zeroday.news ·

A recently disclosed vulnerability in N-able's Passportal password manager reportedly exposed master keys for password vaults. The flaw, which affects a product widely used by Managed Service Providers (MSPs) and Small and Medium Businesses (SMBs), raises concerns about the security of cloud-based password management solutions even after a patch has been applied.

The core issue appears to stem from the architecture of Passportal, particularly its cloud-based design. While a patch has been released, the summary indicates that the product may still present risks. This suggests that the vulnerability might not have been a simple coding error but potentially related to how sensitive cryptographic material, like master keys, is handled or stored within a cloud environment, or how the patch interacts with existing cloud deployments.

In many password managers, a master key is the ultimate credential that unlocks access to all other stored passwords. Its compromise would grant an attacker full access to all credentials managed by the affected vault. For MSPs, this could mean exposure of client credentials, while for SMBs, it could lead to a widespread compromise of internal systems and data.

This class of vulnerability often involves improper key management, insecure storage of cryptographic keys, or flaws in the authentication and authorization mechanisms that protect access to these keys. Cloud-based systems introduce additional complexities, such as securing multi-tenant environments, protecting data in transit and at rest across distributed infrastructure, and ensuring the integrity of cloud service provider components.

Typical mitigation guidance for such issues generally includes immediate application of vendor-supplied patches, robust access controls for administrative interfaces, and strict adherence to the principle of least privilege. Organizations using cloud-based solutions are also advised to implement strong multi-factor authentication, regularly audit access logs, and consider the implications of their cloud provider's security posture and data handling practices.

The report prompts a broader discussion about the suitability of cloud environments for highly sensitive applications like password managers. While cloud solutions offer scalability and accessibility, they also centralize data, making them attractive targets for attackers. The question posed is whether such products should avoid cloud deployment entirely, or if current cloud security paradigms are insufficient for the unique risks associated with master key management.

This incident underscores the ongoing challenge of securing critical infrastructure components, especially those that manage access to other systems. As organizations increasingly rely on third-party and cloud-based services for fundamental security functions, the architectural decisions and security implementations of these vendors become paramount to the overall cybersecurity posture of their customers.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

security

Is Cyber missing the Marque?

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.