Passwordstate’s Comedy of Errors: New Security Patches After Latest Vulnerability Fiasco
Click Studios has rolled out security updates for Passwordstate, tackling an authentication bypass vulnerability. The fix, part of Passwordstate 9.9, also enhances defenses against clickjacking threats. The updates aim to keep the 29,000 customers and 370,000 security professionals relying on Passwordstate safe from cyber shenanigans and digital mischief.

Hot Take:
Click Studios has finally patched a hole in their Passwordstate software that was so big, even a password manager’s arch-nemesis, the “Forgot Password” button, could waltz through unnoticed. Perhaps next time they’ll remember to lock the back door before putting up the ‘Do Not Disturb’ sign.
Key Points:
– Click Studios released a security update for Passwordstate 9.9 (Build 9972) to fix an authentication bypass vulnerability.
– The update also addresses potential clickjacking attacks on its browser extension.
– The vulnerability was discovered by security researcher Marek Tóth.
– Passwordstate is used by 29,000 customers, including government and Fortune 500 companies.
– The company previously faced a supply chain breach in 2021 and resolved multiple flaws in 2022.