The Shared Security Podcast   /     Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass

Description

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported. Three […] The post Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass appeared first on The Shared Security Show.

Summary

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.

Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.

A bug in Meta's Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.

Subtitle
Attacks on password managers and their users continue, three popular health tracking "reward" apps on Google play are doing shady things, and how a bug in Meta's Account Center could allow a hacker to bypass 2FA.
Duration
21:21
Publishing date
2023-02-06 05:00
Link
https://sharedsecurity.net/2023/02/06/password-managers-under-attack-shady-reward-apps-on-google-play-meta-account-center-2fa-bypass/
Contributors
  Tom Eston, Scott Wright, Kevin Johnson
author  
Enclosures
https://traffic.libsyn.com/socialmediasec/Weekly_Edition_E263.mp3
audio/mpeg

Shownotes

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.

Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.

A bug in Meta’s Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.

** Links mentioned on the show *

Convincing, Malicious Google Ads Look to Lift Password Manager Logins
https://www.darkreading.com/threat-intelligence/convincing-malicious-google-ads-password-managers

KeePass disputes vulnerability allowing stealthy password theft
https://www.bleepingcomputer.com/news/security/keepass-disputes-vulnerability-allowing-stealthy-password-theft/

Shady reward apps on Google Play amass 20 million downloads
https://www.bleepingcomputer.com/news/security/shady-reward-apps-on-google-play-amass-20-million-downloads/

Meta’s Account Center came with a 2FA-defeating bug
https://www.theverge.com/2023/1/30/23578033/meta-account-center-bug-2-factor-authentication-sms-email

** Watch this episode on YouTube **

https://youtu.be/g_7UNWmCYgg

** Thank you to our sponsors! **

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

** Subscribe and follow the show **

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass appeared first on The Shared Security Show.