A Password Vault Any Website Could Open (08/20/2026)

August 20, 2026
A Password Vault Any Website Could Open (08/20/2026)
Key Intel / TL;DR
  • N-able's Passportal browser extension answered credential requests from any website, handing over the access and refresh tokens for the whole vault.
  • Passportal is used by roughly 2,500 managed service providers and 165,000 small and medium businesses, and the refresh token lasts 100 days.
  • N-able patched the origin check in a day and did not add end-to-end encryption, so passwords are still decrypted on its servers.
  • Manic relays stolen data off an offline Android phone through nearby infected devices, across up to four hops.
  • NetScaler CVE-2026-19490 scores 9.3 and bypasses authentication on appliances configured as Gateway or as an AAA virtual server.

A password manager that decrypts on the server has to send the key to the server, which means the key exists somewhere a web page can reach for it. Bay Area Labs found that N-able’s Passportal extension would hand those tokens to any site that asked in the right format. The patch arrived the next day and fixed the asking. It did not change the architecture underneath.

Top 5 Critical Security Alerts

1. Passportal Gave Up Its Vault Tokens to Any Website

James Arnott of Bay Area Labs found on July 8 that the N-able Passportal browser extension trusted every message it received without checking where the message came from. A malicious site, or a legitimate one carrying a malicious ad or iframe, could send a get-passwords message and receive the access and refresh tokens back. The access token enumerates and steals every credential in the vault along with time-based one-time codes. The refresh token mints new access tokens for 100 days. Passportal is used by around 2,500 managed service providers and 165,000 small and medium businesses. N-able shipped a patch the following day adding an origin check, and it did not add end-to-end encryption, so Passportal still decrypts passwords on N-able’s servers and returns them over the wire. Dark Reading

Operator Note: Work the blast radius outward, because this product sits at a supply chain chokepoint. One compromised managed service provider holds privileged credentials for every client it serves, and the Site feature lets a provider rebrand Passportal and resell it downstream, which puts twice-removed customers in scope. If your provider uses it, ask two things in writing: was the extension version confirmed updated on every workstation, and were the stored credentials rotated. A patched origin check does nothing about tokens that already left. This is the fourth N-able item we have carried this month.

2. Manic Exfiltrates From a Phone With No Connection

ThreatFabric documented Manic, Android malware with a store-and-forward relay. When the infected phone has no internet, it finds other compromised Android devices over Wi-Fi Direct, Bluetooth RFCOMM, or Bluetooth Low Energy and passes encrypted packets through them toward the command server, up to four hops by default. It intercepts banking and payment credentials and PINs, contacts, call history, messages, notifications, screenshots, location, one-time codes, and recovery phrases, across 169 targeted apps covering banking, cryptocurrency, messaging, and government identity services. The Hacker News

Operator Note: Airplane mode and pulling the SIM are steps in most mobile incident procedures, and against this they buy you nothing if another infected device is within Bluetooth range. That changes the containment answer to physical separation and power off, and it makes the density of infection in a place, an office, a terminal, a conference floor, into a property of the attack. Recovery phrases in the target list means the crypto theft is designed to be irreversible.

3. A 9.3 in NetScaler Bypasses Authentication

CVE-2026-19490 carries a 9.3 and lets an attacker bypass authentication on NetScaler appliances configured as a Gateway, covering SSL VPN, ICA Proxy, CVPN, and RDP Proxy, or as an AAA virtual server. Affected builds are 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, with corresponding FIPS versions. There is no evidence of exploitation yet, and Citrix notes newly disclosed flaws in its products have been a productive target. The Hacker News

Operator Note: These appliances sit at the edge by definition, which is the whole reason they exist, and the affected configurations are the ones people deploy. The gap between a Citrix disclosure and working exploitation has run days rather than weeks on the recent record. Patch this on the timeline you would use for something already under attack.

4. Zimbra SNMP Flaw Under Active Exploitation

Attackers are exploiting a flaw in Zimbra’s Simple Network Management Protocol handling for unauthenticated remote code execution. The Hacker News

Operator Note: SNMP is the protocol nobody audits, because it was configured during the install and has worked quietly ever since. Go find out whether yours is reachable from anywhere it should not be, and whether it is still running the community string the vendor shipped.

5. CDN Tsunami Amplifies Denial of Service 350 Times

The CDN Tsunami technique abuses HTTP/3 translation for up to 350-fold amplification in denial of service attacks. Amplification is the economics of this category, because it decides how much bandwidth an attacker has to rent to knock over a given target. The Hacker News

Operator Note: A 350x multiplier turns a modest botnet into a volumetric threat, and it routes through content delivery infrastructure your own site probably sits behind. Ask your provider directly whether this technique is mitigated on your account rather than assuming the platform handles it.

Additional Security Alerts

Threat Intelligence

  • Medusa has now claimed more than 500 critical infrastructure victims: Up from 300 in February 2025, across healthcare, education, manufacturing, and public health, with the group folding new exploits into its tooling within 24 hours of disclosure. HIPAA Journal
  • Someone lured security researchers with a fake cryptocurrency conference: Targeting the people who write the detections is a durable strategy. TechCrunch
  • SilkParasite is running AI-assisted malware against Central Asia: The campaign we noted yesterday now has the AI assistance detail attached. The Record

Security Breaches & Incidents

  • US Bank is investigating LockBit’s claims under a pay-or-leak deadline: The Register
  • A Delta flight was disrupted through a Wi-Fi hack: In-flight connectivity is a network with passengers on it, and this is the first case most people will have seen. Dark Reading

Security Tools & Best Practices

  • A cryptographic context injection attack could let web pages steal Grok chat data: A page you visit reaching into an assistant’s conversation, which is the same class as the Copilot chain we covered on August 18. The Hacker News
  • An isolated-vm flaw lets sandboxed JavaScript escape to the host: Sandbox escapes matter most where the sandbox is the only control, which is most places that run untrusted code. The Hacker News
  • NASA AIT-GUI flaws could let unauthenticated attackers issue spacecraft commands: The second NASA ground software item this week. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)