- Nov 10, 2017
- 3,250
Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users' password vault credentials.
As the enterprise and consumers move to use unique passwords at every site, it has become essential to use password managers to keep track of all the passwords.
However, unless you use a local password manager, like KeePass, most password managers are cloud-based, allowing users to access their passwords through websites and mobile apps.
These passwords are stored in the cloud in "password vaults" that keep the data in an encrypted format, usually encrypted using users' master passwords.
Recent security breaches at LastPass and credential stuffing attacks at Norton have illustrated that a master password is a weak point for a password vault.
For this reason, threat actors have been spotted creating phishing pages that target your password vault's login credentials, potentially authentication cookies, as once they gain access to these, they have full access to your vault.
Bitwarden password vaults targeted in Google ads phishing attack
Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users' password vault credentials.
www.bleepingcomputer.com