Connect with us

Tech

Password manager Dashlane says hackers stole some customers’ password vaults

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Google’s Gemini nears billion-user milestone

Google is about to add another name to its long list of products with more than a billion users, a list that already includes Search, Gmail, Drive, Android, YouTube, and Chrome. The company said during its Q2 2026 call that the AI assistant Gemini now has over 950 million monthly users.

The company noted that Gemini users have tripled from last year. Earlier, in February, it said that the Gemini app crossed 750 million monthly active users. With this growth, Google’s assistant is in line to compete more closely with OpenAI’s ChatGPT, which hit 1 billion monthly active users in June.

“Users love new agentic features like Daily Brief and our personalized agent, Gemini Spark, which is now available in the U.S. and internationally. We’ve been shipping helpful new features like this at an incredible pace,” Alphabet CEO Sundar Pichai said during the call.

Apart from users on Android, the Gemini app has found a strong user base on iOS with launches like the Nano Banana image generation model. According to Appfigures, the app has been downloaded over 137 million times on iOS in the last 12 months.

In its latest “State of AI” report, the analytics firm Sensor Tower noted that ChatGPT’s market share among AI assistants fell below 50% for the first time. The report, which looked at H1 2026, also noted that Gemini’s share rose to 27.7%.

Many people already use AI assistant apps as a substitute for search. However, Google reported that its search vertical is going strong, partially thanks to the AI-centric overhaul. During this quarter, its Q&A-style AI mode crossed 1 billion users. The company said that it is driving “an incremental increase” in search queries. Google also noted that through hardware engineering, it has reduced the cost of AI mode for the company, despite introducing new models and features.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Google will now let you sign in to your account with a selfie video

Google is adding a selfie video option as a new way for users to log in to their accounts, the company announced on Thursday, joining a growing wave of tech companies betting that biometrics and not passwords are the future of identity verification online. The tech giant says selfie videos give users more options to sign in if they’re ever locked out or don’t have access to their usual phone or computer.

Users set up a selfie video by looking at their device’s camera and completing a few guided head movements — think turning right or left or nodding — to capture multiple angles of their face. If a user is having trouble signing in later, they can take another selfie video to get back into their account, and Google will then compare the new video to the one used at setup to confirm it’s the correct person.

The bigger challenge Google is trying to solve is proving a real human, not a bot or a doctored video, is on the other side of the camera. “When you use a selfie to sign in, we use multiple layers of security to help prevent impersonation attempts like fake photos and videos (i.e., deep fakes),” Google wrote in the blog post. “For example, we match your video against your saved selfie and require you to perform simple movements to prove it’s a live video. We also use our standard security practices to detect and help prevent suspicious sign-in attempts.”

This isn’t just about individual accounts, though. As AI-generated video gets more convincing, “liveness” checks are becoming a baseline requirement for any company handling logins, payments, or sensitive data.

Although the new option could help protect accounts against fraud and help users recover locked accounts, it also raises concerns around user privacy and biometric data collection, an area regulators have increasingly scrutinized as more companies build products around facial and voice data.

Google says selfie videos are stored securely using encryption and remain protected even when they’re not being used, and that users can choose to delete the videos from their Google account at any time.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Meta launched a new AI optimism ad set to a song about human extinction

Meta’s newest advertisement begins with a black-and-white shot of an eye, showing us what someone sees as they read countless panicked headlines about how AI is going to take our jobs, isolate us, and spark a global crisis.

“Some people will have you believe AI is going to make us feel less connected. That it’s going to leave us behind,” a voiceover says. “We couldn’t disagree more.”

Suddenly, the video shifts to color, and shows a cycle of different people opening their eyes and smiling. Then, we see a couple dancing on a rooftop, pointing at a rainbow; a group of teens swimming in a lake; a child frolicking in a field; friends embracing after time apart.

“Call us optimists. Call us dreamers. Call us whatever the hell you want. But we’re betting on people, and we like those odds,” the voiceover says. “The future is for everyone.”

That’s a nice sentiment — pretty convenient for a company betting hundreds of billions of dollars that AI will revolutionize humanity. But the strangest part of the advertisement is not that we’re watching these happy moments play out via Instagram posts. It’s that the soundtrack to the ad is the David Bowie song “Five Years.”

If you are not familiar with this song, I urge you to give it a listen, read the lyrics, and think about what it is trying to say. It seems clear to me, but I studied poetry in college, so as a control for this experiment, I asked my brother — a blockchain analyst who loves Claude Code and does not read for fun — if he could tell me what the song is about.

“I thought climate change at first, then zombie apocalypse, then an asteroid hitting the earth,” he told me. He is correct. It is a song about the human race panicking after learning they will die in a mass-extinction event in five years.

Image Credits:Texts from my brother, a consenting participant in this literary experiment

If you’re not familiar with Bowie’s music, this track might sound happy and inspiring, matching the ad’s upbeat tone. The part of the song that is used for the advertisement was probably chosen because it uses the word “people” over and over again, and without the context of the song, it’s not clear what it’s about.

But if we look at the lines directly preceding this section:

News had just come over
We had five years left to cry in
News guy wept and told us
Earth was really dying
Cried so much his face was wet
Then I knew he was not lying

We “had five years left to cry in” and the “earth was really dying.” It’s pretty bleak.

It is not reassuring to convince people that AI is going to make the world better while playing a song about the end of the world, and yet, this contradictory musical choice seems to have sailed right past everyone at Meta, including CEO Mark Zuckerberg.

“Meta has always believed in giving people the power to share, connect, and shape your world in the ways you want,” he wrote alongside the video. “As we enter this next wave with AI, we continue to believe the future is for everyone. We’re focused on giving every person the tools to reach your full potential and making sure the benefits of technology are distributed to everyone.”

Then again, tech leaders are not known for their literary analysis skills. Meta’s Oculus used to give new hires copies of the science fiction novel “Ready Player One,” which is set in a dystopia in which a tech company making virtual reality products becomes overly powerful and evil. OpenAI CEO Sam Altman has directly cited inspiration from the movie “Her,” which warns us about what can go wrong when we use AI for emotional support. Palantir, a company that builds AI surveillance systems for the government, is named after Palantir, a seeing stone from the “Lord of the Rings” franchise that the Dark Lord uses to spy on his enemies. Elon Musk is currently throwing a fit about the “accuracy” of Christopher Nolan’s blockbuster adaptation of “The Odyssey,” a story with such realistic elements as sea monsters, magic, and divine intervention. These guys make a great argument for the value of studying the humanities.

Meta isn’t alone in its recent promotional foibles. Instead of racing to build AGI, the top AI companies seem to be fighting over who can make the creepiest advertisement. A few weeks ago, Anthropic released an eerie video of its own. As my colleague Lucas Ropek described it:

The ad begins with a video of a burning house (not exactly a heartwarming start) before pivoting to a series of still images. These images include a crowd of people being surveilled by facial recognition, a homeless person sleeping on the street, rows upon rows of tombstones in a cemetery, and what appears to be a group of laborers toiling in a mine where (presumably) raw materials for smartphones are being dug up.

Meanwhile, a voice-over track features different people asking questions like “Can AI be trusted?” and “Who’s gonna hit the brakes if we need to?”

Anthropic is trying to convince us that it understands the risks AI poses to society, and therefore, this is the company that people can trust to develop AI responsibly. The message it actually conveys feels closer to the mood of Bowie’s “Five Years.”

OpenAI CEO Sam Altman responded to the Anthropic ad, “I thought this was satire, kept looking for the handle to be spelled c1audeai or something.”

As these companies spar to control the public perception of AI, their efforts don’t seem to be making much progress. A recent Pew survey found that only 16% of Americans think that AI’s impact on society over the next 20 years will be positive, and 40% believe it will have a negative impact. Better luck next time, Meta.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading