Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across multiple devices can install Enpass on Windows, macOS, Linux, Android, and iOS. Browser extensions are available for Chrome

Enpass Password Manager offers a comprehensive solution for storing sensitive information such as passwords, passkeys, payment cards, and secure notes in encrypted vaults. A key distinguishing feature of Enpass is its departure from proprietary cloud storage models, allowing users to select their preferred cloud service or store data locally.
The application is available across a wide range of platforms, including Windows, macOS, Linux, Android, and iOS, with browser extensions supporting Chrome, Edge, Firefox, Safari, Brave, Opera, and Vivaldi. This broad compatibility ensures users can access their credentials across various devices.
Upon initial setup, users can choose between personal or business use and create an account via email or Sign in with Apple. Enpass provides multiple storage options for vaults, including iCloud, Google Drive, Dropbox, OneDrive, Nextcloud, WebDAV, Wi-Fi Sync, and local device storage. Existing vaults can also be restored from backup files or transferred over Wi-Fi.
The user interface prioritizes security, displaying a Security Score that summarizes password health and offering quick access to features like Face ID, AutoFill, and compromised password monitoring. The app automatically tracks weak, compromised, and passkey-enabled accounts.
Enpass includes an extensive array of templates for various record types, such as logins, credit cards, identities, secure notes, bank accounts, passports, travel documents, software licenses, crypto wallets, and insurance policies. These are organized under a "Browse" section, with dedicated categories for passkeys, one-time authentication codes, attachments, archived items, and deleted entries.
A built-in password generator allows users to configure password length, character types (uppercase, lowercase, numbers, symbols), and generate pronounceable passwords, each receiving a strength rating before saving.
For convenience and security, Enpass supports AutoFill for usernames, passwords, passkeys, authentication codes, and payment information in apps and Safari, requiring verification via Face ID, Touch ID, PIN, or a master password. The application integrates TOTP support, eliminating the need for a separate authenticator app, and stores passkeys alongside other login credentials.
Additional features include support for unlimited vaults, custom categories, tags, attachments, password history, breach monitoring, and password auditing. Users can maintain separate vaults for work and personal credentials without needing multiple accounts. Desktop applications also facilitate importing data from other password managers.
Enpass is designed for users who prioritize control over their encrypted vault storage while still benefiting from modern password management features like passkeys, AutoFill, breach monitoring, and cross-platform synchronization. Its extensive platform support and flexible storage options make it a versatile choice for users operating across diverse operating systems and devices.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early