Cybersecurity Videos
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityVideosPassword Managers Are Swiss Cheese - Threat Wire
Cybersecurity

Password Managers Are Swiss Cheese - Threat Wire

•February 19, 2026
0
Hak5
Hak5•Feb 19, 2026

Why It Matters

These vulnerabilities expose millions to remote code execution, privacy intrusion, and credential compromise, compelling organizations to accelerate patching, scrutinize biometric verification, and reconsider password‑manager security architectures.

Key Takeaways

  • •Windows 11 Notepad's markdown support creates RCE vulnerability (CVE‑2026‑2841).
  • •Discord plans facial‑age verification, sparking privacy concerns among users.
  • •ETH Zurich study finds multiple exploitable attacks on major password managers.
  • •Bitwarden and LastPass simulations achieved full vault compromise in tests.
  • •Vendors downplay findings, citing low severity and no wild exploits yet.

Summary

The latest Threatwire episode delivers a packed cyber‑security briefing, spotlighting three headline stories: a critical flaw in Windows 11’s revamped Notepad, Discord’s upcoming facial‑age verification system, and a new academic analysis exposing weaknesses in leading password managers.

Microsoft’s Notepad now parses markdown, inadvertently allowing specially crafted files to hide malicious URIs that trigger remote code execution. The issue, catalogued as CVE‑2026‑2841, earned a 7.8 CVSS rating. Meanwhile, Discord announced it will roll out on‑device facial age estimation to gate age‑restricted content, assuring users that images never leave the device, yet the move has ignited a privacy backlash. The ETH‑Zurich researchers simulated full server takeovers of Bitwarden, LastPass, and Dashlane, uncovering 12, 7, and 6 viable attack vectors respectively; Bitwarden and LastPass showed complete vault compromise, while Dashlane suffered shared‑vault exposure.

Microsoft described the Notepad bug as “improper neutralization of special elements used in a command,” and Discord’s FAQ emphasized that only an age range is retained, never the identity. The password‑manager study highlighted real‑world attack scenarios, prompting Bitwarden to reiterate that no breach has occurred and all three vendors labeled the findings low‑severity. The discussion also referenced recent supply‑chain compromises, such as Notepad++’s update‑server breach, underscoring the plausibility of these attacks.

Collectively, these developments warn enterprises and consumers alike that even trusted utilities and widely‑adopted security tools can harbor exploitable flaws. Immediate patching of Notepad, careful evaluation of facial‑recognition deployments, and a reassessment of password‑manager cryptography are essential steps to mitigate potential credential theft and privacy erosion.

Original Description

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev
Want to work with Ali? endingwithalicollabs@gmail.com
[❗] Join the Patreon→ https://patreon.com/threatwire
0:00 0 - Intro
1 - NotePad's Punched Holes
2 - Discord Facial Age Recognition
2.5 - Comment Section
3 - Swiss Holes In Password Manager
4 - Other News
5 - Outro
LINKS
🔗 Story 1: NotePad's Punched Holes
https://www.cve.org/CVERecord?id=CVE-2026-20841
https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-flaw-let-files-execute-silently-via-markdown-links/
https://foss-daily.org/posts/microsoft-notepad-2026/
🔗 Story 2: Discord Facial Age Recognition
https://www.youtube.com/@UCxaaULLk6UCnRl5VKRc7G0A
https://discord.com/safety/how-discord-is-building-safer-experiences-for-teens
https://www.theverge.com/tech/875309/discord-age-verification-global-roll-out
https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally
🔗 Story 3: Swiss Holes In Password Manager
https://www.itpro.com/security/researchers-called-on-lastpass-dashlane-and-bitwarden-to-up-defenses-after-severe-flaws-put-60-million-users-at-risk-heres-how-each-company-responded
https://ethz.ch/en/news-and-events/eth-news/news/2026/02/password-managers-less-secure-than-promised.html
🔗 Story 4: Other News
https://office365itpros.com/2026/02/13/dlp-policy-for-copilot-bug/
https://www.theregister.com/2026/02/15/exl3harris_exec_sold_8_zeroday/
https://thecyberexpress.com/cve-2026-2441-google-chrome/
https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/
https://www.bleepingcomputer.com/news/security/one-threat-actor-responsible-for-83-percent-of-recent-ivanti-rce-attacks/
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Our Site → https://www.hak5.org
Shop → http://hakshop.myshopify.com/
Community → https://www.hak5.org/community
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1
Support → https://www.patreon.com/threatwire
Contact Us → http://www.twitter.com/hak5
____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
0

Comments

Want to join the conversation?

Loading comments...