Microsoft bundled a password manager into Windows 10 with a critical security bug
As revealed by the researcher to Microsoft, the flaw was essentially a browser plugin bug that could enable malicious websites to steal passwords.


Microsoft Windows 10.[/caption]As per a report by Engadget, it was Google's Project Zero researcher Tavis Ormandy who discovered the flaw and disclosed it to Microsoft. The flaw was essentially a browser plugin bug that could enable malicious websites to steal passwords. To demonstrate how easy it is to steal passwords with the plugin installed, Ormandy linked to a working demo of the bug stealing a user's Twitter password.Ormandy explained in his disclosure post, "I've heard of Keeper, I remember filing a bug a while ago about how they were injecting privileged UI into pages. I checked and they're doing the same thing again with this version. Nevertheless, this is a complete compromise of Keeper security, allowing any website to steal any password."A Microsoft spokesperson responded to ArsTechnica in a report stating the Keeper team had come up with a patch that fixes the problem, 24-hours after Ormandy had brought the bug to its notice. Microsoft attempted to reassure its users by stating that the bug should not be any consequence if the software is up to date, but did not respond to why it failed to catch the bug in its security tests before it was bundled with Windows 10.

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
