This Week In Security: Terrapin, Seized Unseized, And Autospill

There’s a new SSH vulnerability, Terrapin (pdf paper), and it’s got the potential to be nasty — but only in an extremely limited circumstance. To understand the problem, we have t…

Hackaday
Un nuovo attacco colpisce tutti i password manager Android, cos'è AutoSpill e come proteggersi

AutoSpill minaccia i password manager su Android, ecco tutto quello che dovreste sapere a riguardo e come agire per proteggervi.

Tom's Hardware

How worried should we be about the “AutoSpill” credential leak in #Android #password managers?
#security #autospill

https://arstechnica.com/?p=1990601

How worried should we be about the “AutoSpill” credential leak in Android password managers?

This newly discovered vulnerability is real, but it's more nuanced than that.

Ars Technica
https://onexception.dev/news/1078253/password-managers-vulnerable-to-autospill-attack-on-android-devices?utm_source=mastodon #passwordmanagers #security #AutoSpill #Android
Password managers are convenient for storing and generating secure passwords, but they can also be vulnerable to attacks. Researchers have discovered a new exploit called AutoSpill that targets certain password managers on Android devices. This attack takes advantage of WebView resources to obtain user credentials, potentia
Are Password Managers Vulnerable to AutoSpill Attack on Android Devices?

Password managers are convenient for storing and generating secure passwords, but they can also be vulnerable to attacks. Researchers have discovered a new exploit called AutoSpill that targets certain password managers on Android devices. This attack takes advantage of WebView resources to obtain user credentials, potentially compromising all stored passwords. The researchers have reported their findings to the affected companies and the Android security team, who are working on solutions to address the issue.

Менеджери паролів на Android «‎видають» облікові дані користувачів — через нову атаку AutoSpill https://itc.ua/ua/novini/menedzhery-paroliv-na-android-vydayut-oblikovi-dani-korystuvachiv-cherez-novu-ataku-autospill/ #Менеджерипаролів #AutoSpill #Смартфони #LastPass #Android #Новини #Enpass #Google #Софт
Менеджери паролів на Android «‎видають» облікові дані користувачів — через нову атаку AutoSpill

Кілька популярних мобільних менеджерів паролів ненавмисно розкривають облікові

ITC.ua
Менеджери паролів на Android «‎видають» облікові дані користувачів — через нову атаку AutoSpill https://itc.ua/ua/novini/menedzhery-paroliv-na-android-vydayut-oblikovi-dani-korystuvachiv-cherez-novu-ataku-autospill/ #Менеджерипаролів #AutoSpill #Смартфони #LastPass #Android #Новини #Enpass #Google #Софт
Менеджери паролів на Android «‎видають» облікові дані користувачів — через нову атаку AutoSpill

Кілька популярних мобільних менеджерів паролів ненавмисно розкривають облікові

ITC.ua

The #AutoSpill vulnerability arises from Android’s failure to enforce secure handling of auto-filled data, leading to potential leaks or capture by the host app.

#Cybersecurity #Google #Vulnerability #Android #PasswordManager

https://cybersec84.wordpress.com/2023/12/09/android-password-managers-at-risk-from-autospill-attack/

Android Password Managers At Risk From AutoSpill Attack

Security researchers have unveiled a new threat named AutoSpill, designed to pilfer account credentials on Android devices during the autofill process. Presenting their findings at the Black Hat Eu…

CyberSec84 | Cybersecurity news.
AutoSpill: Passwortmanager legen unter Android Zugangsdaten offen

Eine Schwachstelle namens AutoSpill sorgt dafür, dass Zugangsdaten aus Passwortmanagern unter Android in die falschen Hände geraten können.

ComputerBase
AutoSpill: Sicherheitslücke in Android gefährdet Passwortmanager

AutoSpill ist gefährlich. Denn jede Anwendung, die zur Anmeldung auf anderen Websites auffordert, kann auf sensible Informationen zugreifen.

Tarnkappe.info
Your mobile password manager might be exposing your credentials | TechCrunch

Researchers say the "AutoSpill" bug can exposes mobile-stored credentials. One password manager company said they plan to make changes.

TechCrunch