# passwords

Published articles for passwords.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## New SymfonyCasts Course: Symfony Security - The Basics

DevFeed: [New SymfonyCasts Course: Symfony Security - The Basics](<https://devfeed.tech/articles/new-symfonycasts-course-symfony-security-the-basics-30915.md>)

Original publisher: [Read original article](<https://symfony.com/blog/new-symfonycasts-course-symfony-security-the-basics>)

Author: Kevin Bond

Published: 2026-09-16T09:34:00Z

Content type: release

Language: en

Sources: [Symfony Blog](<https://devfeed.tech/sources/symfony-blog.md>)

Topics: [Symfony](<https://devfeed.tech/topics/symfony.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [firewalls](<https://devfeed.tech/topics/firewalls.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [controllers](<https://devfeed.tech/tags/controllers.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [forms](<https://devfeed.tech/tags/forms.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [security-events](<https://devfeed.tech/tags/security-events.md>), [symfony](<https://devfeed.tech/tags/symfony.md>)

### AI overview

SymfonyCasts announces a new course covering the fundamentals of Symfony Security. The course builds an authentication and authorization system with Symfony 8, and the material also works with Symfony 7.

### Source excerpt

Authentication, authorization, roles, voters, firewalls... there's a lot happening inside Symfony's Security system. But once you understand how the pieces fit together, it's a powerful and flexible system for answering two fundamental questions: who is this...

## Support the well-known change password URL with Appwrite Auth

DevFeed: [Support the well-known change password URL with Appwrite Auth](<https://devfeed.tech/articles/support-the-well-known-change-password-url-with-appwrite-auth-31444.md>)

Original publisher: [Read original article](<https://appwrite.io/blog/post/well-known-change-password-url>)

Author: Atharva Deosthale

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Appwrite Blog](<https://devfeed.tech/sources/appwrite-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Appwrite](<https://devfeed.tech/topics/appwrite.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [W3C](<https://devfeed.tech/topics/w3c.md>)

Tags: [bitwarden](<https://devfeed.tech/tags/bitwarden.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [tutorials](<https://devfeed.tech/tags/tutorials.md>), [w3c](<https://devfeed.tech/tags/w3c.md>)

### AI overview

This tutorial shows how to support the well-known change password URL in a TanStack Start app using Appwrite Auth. It explains the redirect, the change-password form for signed-out visitors, autocomplete hints, and deployment to Appwrite Sites.

### Source excerpt

Password managers open /.well-known/change-password when they find a leaked or weak password. Add the redirect and a change password page backed by Appwrite Auth.

## HBO Max's verified Reddit account hijacked to spread malware

DevFeed: [HBO Max's verified Reddit account hijacked to spread malware](<https://devfeed.tech/articles/hbo-max-s-verified-reddit-account-hijacked-to-spread-malware-26612.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware>)

Author: Pieter Arntz

Published: 2026-09-15T11:51:03Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pasteswitch](<https://devfeed.tech/tags/pasteswitch.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Cybercriminals hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads over about 48 hours. The ads promoted fake software and used ClickFix-style instructions to distribute infostealers and cryptocurrency clipboard hijackers to macOS and Windows users.

### Source excerpt

Cybercriminals used HBO Max's verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

## UK.gov begins killing off passwords for 23 million users

DevFeed: [UK.gov begins killing off passwords for 23 million users](<https://devfeed.tech/articles/uk-gov-begins-killing-off-passwords-for-23-million-users-17411.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088>)

Author: Carly Page

Published: 2026-09-14T09:16:11Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [government-of-the-united-kingdom](<https://devfeed.tech/tags/government-of-the-united-kingdom.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>), [whitehall](<https://devfeed.tech/tags/whitehall.md>)

### AI overview

The UK government is beginning to replace passwords with passkeys for 23 million users. The change is intended to reduce phishing problems and save Whitehall approximately GBP 600 per day in SMS costs.

### Source excerpt

Passkeys promise fewer phishing headaches - and GBP 600 a day off Whitehall's SMS bill

## JDK 27 Runtime Updates Release Notes

DevFeed: [JDK 27 Runtime Updates Release Notes](<https://devfeed.tech/articles/jdk-27-runtime-updates-release-notes-15132.md>)

Original publisher: [Read original article](<https://inside.java/2026/09/12/jdk-27-runtime-updates/>)

Author: Billy Korando

Published: 2026-09-12T00:00:00Z

Content type: release

Language: en

Sources: [Inside Java](<https://devfeed.tech/sources/inside-java.md>)

Topics: [JDK 27](<https://devfeed.tech/topics/jdk-27.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Java](<https://devfeed.tech/topics/java.md>)

Tags: [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [gc](<https://devfeed.tech/tags/gc.md>), [jdk-27](<https://devfeed.tech/tags/jdk-27.md>), [memory](<https://devfeed.tech/tags/memory.md>), [net-conf](<https://devfeed.tech/tags/net-conf.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>)

### AI overview

This article reviews runtime updates in JDK 27, including G1GC becoming the default garbage collector in all cases, Compact Object Headers being enabled by default, and improved JFR redaction and filtering for sensitive information such as passwords and API keys.

### Source excerpt

Let's review the performance updates, new runtime features, and other changes to existing features that are in the JDK 27 release!

## Accounts & Self-Service UX Research Update and Expansion: 3 Key Takeaways

DevFeed: [Accounts & Self-Service UX Research Update and Expansion: 3 Key Takeaways](<https://devfeed.tech/articles/accounts-self-service-ux-research-update-and-expansion-3-key-takeaways-9361.md>)

Original publisher: [Read original article](<https://feeds.baymard.com/link/9825/17443305/accounts-and-self-service-ux-research-2026>)

Author: Sally Collins

Published: 2026-09-09T08:05:00Z

Content type: article

Language: en

Sources: [Baymard Institute](<https://devfeed.tech/sources/baymard-institute.md>)

Topics: [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [insights](<https://devfeed.tech/tags/insights.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Baymard's updated Accounts & Self-Service UX research examines how ecommerce account experiences have changed since 2018. Based on more than 4,000 hours of research, 1,400 usability issues, and a survey of over 1,000 US adults, the article highlights account security and sign-in changes, including passkeys, one-time passcodes, and two-factor authentication.

### Source excerpt

(Note: Unfortunately, e-mail and RSS don't support advanced layouts and features. If the graphics in this article look strange, you may want to read the article in your web browser.) Key Takeaways Baymard has new research on Accounts & Self-Service UX The research uncovered UX issues and identified UX solutions specific to the Accounts area of ecommerce sites Much has changed in account security and sign in, order management and tracking, and order returns since our last large-scale research in 2018 Key Stats 4,000+ new hours of Accounts & Self-Service research 1,400+ usability issues observed in testing 1,000+ US adults surveyed as part of our complementary quantitative research Today at Baymard, we're announcing the launch of our new updated and expanded Accounts & Self-Service UX research. We first investigated UX issues in Accounts & Self-Service in 2018. In this update, we've retested all the UX issues observed in 2018, verified all our UX solutions, wrote new guidelines based on newly observed Accounts & Self-Service UX issues, and rewritten the bulk of our verified guidelines for improved usefulness and clarity. This work has resulted in 57 new and updated Accounts & Self-Service guidelines based on 1,400+ usability issues observed during testing. The 57 guidelines are a key foundation for ensuring a high-performing Accounts and Self-Service UX. Additionally, we've included mobile test observations for the first time. As a result, this study represents our most comprehensive findings on Accounts & Self Service ecommerce UX. In this article, we'll highlight 3 high-level insights from our new Accounts & Self-Service UX research findings. New Insights for Accounts & Self-Service UX Compared to 2018, the landscape of Accounts & Self-Service has changed dramatically, particularly in 3 areas. 1) Account Security and Sign In At J.Crew, participants updating their passwords were provided no guidance regarding the site's password requirements, and they were unable to

## StreamRat Android malware spreads through Meta and TikTok ads

DevFeed: [StreamRat Android malware spreads through Meta and TikTok ads](<https://devfeed.tech/articles/streamrat-android-malware-spreads-through-meta-and-tiktok-ads-8441.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads>)

Author: Pieter Arntz

Published: 2026-09-03T16:04:24Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [advertising](<https://devfeed.tech/tags/advertising.md>), [android](<https://devfeed.tech/tags/android.md>), [browser](<https://devfeed.tech/tags/browser.md>), [malware](<https://devfeed.tech/tags/malware.md>), [meta](<https://devfeed.tech/tags/meta.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [streamrat](<https://devfeed.tech/tags/streamrat.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [tiktok](<https://devfeed.tech/tags/tiktok.md>)

### AI overview

A malicious ad campaign used fake streaming-service promotions on Meta and TikTok to distribute the StreamRat Android banking Trojan. The campaign directed Android users to a tailored download page that coached them past security warnings and enabled credential theft and remote device control.

### Source excerpt

Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

## Introducing universal sign-in: a seamless solution for every way you login

DevFeed: [Introducing universal sign-in: a seamless solution for every way you login](<https://devfeed.tech/articles/introducing-universal-sign-in-a-seamless-solution-for-every-way-you-login-1935.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-universal-sign-in>)

Author: info@1password.com (Travis Hogan and Brandon Lucier)

Published: 2026-09-03T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [1password-in-the-browser](<https://devfeed.tech/tags/1password-in-the-browser.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extension](<https://devfeed.tech/tags/extension.md>), [launch](<https://devfeed.tech/tags/launch.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password releases universal sign-in in its browser extension, presenting passwords, passkeys, one-time codes, social logins, and managed-app methods in one prompt.

### Source excerpt

Today we're releasing universal sign-in, a new experience from 1Password that provides a seamless and secure way to sign into any site with your preferred method. It's currently available to all customers in the latest version of the 1Password browser extension. A single prompt for every sign-in Signing in doesn't happen one way anymore. A single site might support passwords, passkeys, or third-party providers like Google. Over the last several years, 1Password has evolved to support all major authentication methods used today (passwords, passkeys, 2FA, social logins, OIDC and SAML). But the authentication experience varied because of differences with the underlying technologies. Not having a consistent way to use every authentication type 1Password offered meant needing to remember which third-party provider account you used, manually submitting pages, or needing to find and click sign-in fields. No password manager on the market had a single, consistent way to let you sign in, until now. Universal sign-in means that when you land on a login page, 1Password displays a single prompt to sign in using the authentication method you've chosen for that website. No need to remember how you've logged into the website in the past; passwords, passkeys, one-time codes, social logins, and company-managed apps will all appear in the same, intuitive prompt. Simply pick which account you'd like to sign in with, and 1Password handles the rest. How it works Visit a login page, or launch a saved login in 1Password with an available sign-in URL. The universal sign-in prompt appears at the top of the login page using our new advanced field analysis. It'll appear when you need it, and disappear when you don't. Every account and available authentication method is listed and selectable within the universal sign-in prompt. Choose the login you'd like to use. Over time, 1Password also learns which accounts and methods you prefer using for that site. 1Password then automatically fills your

## Continuous identity intelligence for post-login security evaluation

DevFeed: [Continuous identity intelligence for post-login security evaluation](<https://devfeed.tech/articles/when-ai-takes-the-wheel-the-rise-of-invisible-identity-intelligence-in-2026-16111.md>)

Original publisher: [Read original article](<https://www.twilio.com/en-us/blog/insights/invisible-identity-intelligence>)

Author: Catie Kolander

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Twilio Blog](<https://devfeed.tech/sources/twilio-blog.md>)

Topics: [Digital Security](<https://devfeed.tech/topics/digital-security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [industry-insights](<https://devfeed.tech/tags/industry-insights.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that passwords, MFA, and passkeys secure only the initial login, while later session activity may become risky. It advocates continuous post-login identity and context evaluation, delegated authority, communication guardrails, and auditability for sensitive actions.

### Source excerpt

Secure your platform in the AI era with continuous identity intelligence. Learn how.

## From one switch to a control panel: meet \`dataCollection\`

DevFeed: [From one switch to a control panel: meet \`dataCollection\`](<https://devfeed.tech/articles/from-one-switch-to-a-control-panel-meet-datacollection-24094.md>)

Original publisher: [Read original article](<https://blog.sentry.io/datacollection-control-panel/>)

Author: Sigrid Huemer

Published: 2026-08-28T09:00:00Z

Content type: release

Language: en

Sources: [Sentry Blog](<https://devfeed.tech/sources/sentry-blog.md>)

Topics: [SDKs](<https://devfeed.tech/topics/sdks.md>), [data](<https://devfeed.tech/topics/data.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [api-keys](<https://devfeed.tech/tags/api-keys.md>), [data](<https://devfeed.tech/tags/data.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

Sentry is replacing the all-or-nothing `sendDefaultPii` setting with `dataCollection`, which provides granular control over automatically collected data such as user information, headers, request bodies, and GenAI data. The change is rolling out across Sentry SDKs, with JavaScript SDK v11 making it the default and collecting more data than v10 by default.

### Source excerpt

Sentry SDKs replace the `sendDefaultPii` boolean with `dataCollection`, granular options for user data, headers, bodies, GenAI data, and more.

## 1Password product enhancements: Smarter autofill, phishing prevention, and more

DevFeed: [1Password product enhancements: Smarter autofill, phishing prevention, and more](<https://devfeed.tech/articles/1password-product-enhancements-smarter-autofill-phishing-prevention-and-more-1884.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-product-enhancements-smarter-autofill-phishing-prevention>)

Author: info@1password.com (Elaine Atwell)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [macos](<https://devfeed.tech/tags/macos.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [saas](<https://devfeed.tech/tags/saas.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This English developer article presents recent 1Password product enhancements focused on smoother credential management and sign-in. It covers universal sign-in for personal and business accounts, macOS autofill, native password generation and saving in iOS 26.2, an iOS autofill health check, and improvements related to data ownership and migration.

### Source excerpt

At 1Password, we're constantly working to make life simpler and more secure for our users, from the biggest businesses to each individual who signs up for our password manager. Over the past few months, we've been rolling out a slew of updates designed to make a difference for customers, whether you're using us at home, at work, or (ideally) both. Here are some of the latest developments for you to explore. Upgrades to autofill and autosave One of the most immediate benefits of using 1Password in your daily life is a smooth experience of creating, saving, and inputting your credentials and logins. These updates help you get the most out of that experience, with fewer clicks, on the devices you already use. Universal sign-in for personal and business accounts Signing in just got simpler with a smarter, modern experience using a one-click prompt. Now in beta, 1Password seamlessly logs you into any site or service at the right moment using your desired authentication method (passwords, passkeys, social sign in, OIDC, SAML*). We remove all the extra steps so you sign in quickly and smoothly, while staying secure. *SAML is only available for business accounts that also have 1Password SaaS Manager. macOS autofill 1Password now works as a native Credential Provider on macOS, so your logins and passkeys easily fill right inside Safari and other desktop apps. Save and generate passwords in iOS 26.2 The password creation experience on iPhone and iPad should happen at the exact moment you need it, especially when you're signing up for a new account. With this update, 1Password shows up natively in Safari and other iOS-native apps so you can generate and save a strong password right in the account creation flow, without leaving what you're doing. This makes it easier to capture credentials when they're created and keeps account setup uninterrupted. Autofill health check for iOS The reliability of iOS autofill depends on a tangle of systems, and when there's a problem with one,

## Environment variables now use Config and Secret types

DevFeed: [Environment variables now use Config and Secret types](<https://devfeed.tech/articles/environment-variables-now-use-config-and-secret-types-917.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/environment-variables-now-use-config-and-secret-types>)

Author: Brooke Mosby

Published: 2026-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [configuration](<https://devfeed.tech/topics/configuration.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [config](<https://devfeed.tech/tags/config.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel now uses Config and Secret types for environment variables instead of the Sensitive toggle. Config values remain readable to authorized members, while Secret values remain available to deployments but cannot be viewed or retrieved after saving. The update also introduces a policy for separating Production secret values and adds CLI support through visibility settings.

### Source excerpt

When you add or edit an environment variable in Vercel, you now choose Config or Secret instead of using the Sensitive toggle. Existing variables marked Sensitive are automatically treated as Secrets and continue to work without migration. Config: The value remains readable after saving for members with access. Use Config for non-sensitive values you may need to inspect later, such as variables with a public framework prefix. Secret: The value remains available to your deployments and can be replaced, but members cannot view or retrieve it after saving. Use Secret for passwords, API keys, and tokens. You can select an environment or Preview branch for each value. The environment variable list in the dashboard shows each variable's type and where it applies. Team policy changes The Enforce Sensitive Environment Variables team policy is deprecated with this update. When enabled, it required every environment variable created by a team member to be Sensitive, including non-sensitive configuration. With Config and Secret types, members can choose the appropriate type for each variable. A new Separate Production Secret Values policy is available in your Security settings. When enabled, the Production value for a Secret must differ from the values used for the same key in Preview, Development, and custom environments. If your team had the legacy policy enabled, confirm whether the Separate Production Secret Values policy should be enabled for your team. The deprecated policy is no longer enforced by the Vercel CLI. Set variable types from the CLI To choose whether an environment variable is a Config or Secret from the CLI, pass --visibility config or --visibility secret to vercel env add or vercel env update: The existing flags continue to work. When --visibility is omitted, --no-sensitive maps to Config and --sensitive maps to Secret. After adding or updating a variable, the CLI output shows its type under Visibility. Learn more in the Environment Variables documentation

## 1Password's back-to-school tips for the digital world

DevFeed: [1Password's back-to-school tips for the digital world](<https://devfeed.tech/articles/1password-s-back-to-school-tips-for-the-digital-world-1922.md>)

Original publisher: [Read original article](<https://1password.com/blog/getting-started-students-and-families>)

Author: info@1password.com (1Password)

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Digital Security](<https://devfeed.tech/topics/digital-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [claude](<https://devfeed.tech/tags/claude.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [guide](<https://devfeed.tech/tags/guide.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tips-advice](<https://devfeed.tech/tags/tips-advice.md>)

### AI overview

1Password's back-to-school guide offers parents and students practical advice for staying secure and organized in the digital world. It focuses on evaluating AI tools, protecting personal information and passwords, avoiding phishing and password reuse, and building safer online habits.

### Source excerpt

It happened again. We blinked, and suddenly summer's over and it's time to register for classes. The horror! While the start of a new school year has always been a stressful time for parents and students, the growing number of accounts, apps, and devices students have been responsible for in recent years has made it even more complicated. To help manage the stress, 1Password is sharing our favorite back-to-school security tips for parents and students of all ages, so you can start the 2026 school year secure and organized. School security 101: From AI to user IDs With more AI tools emerging every day, it can be difficult to track which ones are trustworthy. AI tools and agents need access to a lot of data in order to function; AI adopters, and concerned parents, should take care about what data is being shared with the AI. It's worth learning what AI-based tools your kids are using, and educating them about what kinds of information they should never share with a chatbot. That includes sensitive personal information, but it also includes things like passwords, which no AI user should paste directly into a chat window just because a helpful-seeming agent asked for them. Tools like 1Password for Claude offer a safe way for the AI power users in your family to experiment with agents. For any parents, whether your kids are entering elementary school or going off to college for the first time, they can benefit from a talk about AI tools and online safety. You don't have to scare your kids away from technology, nor should you try to control everything they do online. Instead, set them up for success with knowledge and preparation. 💡Heading to college or university? Check out our blog, A college student's guide to better digital security. Make strong passwords a habit now Despite the perception that young people today are tech-savvy, that doesn't mean they're secure. With apps for school, home, and socializing, the average student is creating more accounts than they can po

## CSS:the bomb inside your inbox

DevFeed: [CSS:the bomb inside your inbox](<https://devfeed.tech/articles/css-the-bomb-inside-your-inbox-7674.md>)

Original publisher: [Read original article](<https://portswigger.net/research/css-the-bomb-inside-your-inbox>)

Author: Gareth Heyes

Published: 2026-08-06T22:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [modern web development](<https://devfeed.tech/topics/modern-web-development.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [atlas](<https://devfeed.tech/tags/atlas.md>), [browser](<https://devfeed.tech/tags/browser.md>), [bug](<https://devfeed.tech/tags/bug.md>), [css](<https://devfeed.tech/tags/css.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [html](<https://devfeed.tech/tags/html.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [ui](<https://devfeed.tech/tags/ui.md>)

### AI overview

A security paper on abusing discrepancies between CSS/HTML sanitizers and browser rendering in webmail clients. It describes techniques that can cross trust boundaries, spoof UI actions, exfiltrate tokens, and steal passwords, including an Outlook UI-control issue involving HTML labels.

### Source excerpt

Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this

## Remove standing access before AI agents exploit it

DevFeed: [Remove standing access before AI agents exploit it](<https://devfeed.tech/articles/remove-standing-access-before-ai-agents-exploit-it-1950.md>)

Original publisher: [Read original article](<https://1password.com/blog/remove-standing-access-before-ai-agents-exploit-it>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-08-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [incident](<https://devfeed.tech/topics/incident.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article argues that AI-driven autonomous systems can rapidly discover and exploit standing credentials after gaining access to enterprise environments. It recommends removing unnecessary access, vaulting plaintext secrets, and reducing the blast radius of credential-based attacks.

### Source excerpt

AI has changed the calculus of a credential attack. Before, finding and exploiting credentials in an enterprise environment required time, patience, and human judgment. An attacker had to decide which accounts were worth testing and which systems were worth reaching. Many credentials never made the list. By contrast, an autonomous system that gains a foothold in a victim's systems has no need to be picky. It can sweep an environment in moments, scooping up API keys, service account tokens, OAuth tokens, cloud credentials, and plaintext secrets on developer devices. It authenticates with whatever it finds and moves laterally as far as standing access allows, one credential opening the next, at machine speed. An attacker with AI doesn't need to choose targets. Everything accessible is worth exploiting. Recent high-profile incidents with experimental AI models have shown that pattern in action. Entry points differed: software exploits in two cases, weak passwords in a third. But what followed was the same in each incident: automated systems swept for whatever credentials the environment offered and moved as far as standing access would carry them. In one documented case, that meant more than 17,000 recorded attacker events over a single weekend. These stories are just early indicators of what defenders will soon be facing as these experimental models become commonly available services. As autonomous systems become more capable and more widely deployed, credential sweeps after breaches will become faster, more thorough, and harder to detect. Any enterprise running AI workloads, AI coding tools, or developer workflows on shared infrastructure has accumulated the same kind of exposure that made these headline-grabbing attacks successful: service accounts whose permissions grew beyond their original purpose, API keys that were never rotated, and secrets left in plaintext on developer devices because they were easier to use that way. In the face of what is coming, strengthe

## Hpf-passwd: Easily change passwords while using \`hashedPasswordFile\`

DevFeed: [Hpf-passwd: Easily change passwords while using \`hashedPasswordFile\`](<https://devfeed.tech/articles/hpf-passwd-easily-change-passwords-while-using-hashedpasswordfile-31351.md>)

Original publisher: [Read original article](<https://discourse.nixos.org/t/hpf-passwd-easily-change-passwords-while-using-hashedpasswordfile/79254>)

Author: Anomalocaris

Published: 2026-07-31T01:54:54Z

Content type: article

Language: en

Sources: [Announcements - NixOS Discourse](<https://devfeed.tech/sources/announcements-nixos-discourse.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [passwd](<https://devfeed.tech/topics/passwd.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [account](<https://devfeed.tech/topics/account.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [config](<https://devfeed.tech/tags/config.md>), [passwd](<https://devfeed.tech/tags/passwd.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [script](<https://devfeed.tech/tags/script.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

The author introduces hpf-passwd, a standalone script for changing passwords for NixOS user accounts configured with hashedPasswordFile. It imitates passwd's semantics but is not a complete drop-in replacement and currently lacks features such as password expiration management.

### Source excerpt

For a while, I've used users.users.*.hashedPasswordFile with users.mutableUsers = true to minimize configuration drift. However, as far as I could tell, no one had created a convenient way to set or change these passwords, so I wrote a quick and dirty script and called it a day. More recently, I was reworking this script and realized I could decouple it completely from my config, spin it off into its own project, and polish it up so other people could benefit from it. The result is hpf-passwd. Currently, it's a single script that mainly just lets you change the password of a given user account, provided it has users.users.<username>.hashedPasswordFile set. Befitting its name, it tries to mimic passwd's semantics to try to be intuitive. However, it can never be a 1:1 drop-in replacement. As far as I am aware, there is no way to set things like expiration dates for passwords managed like this. I plan to eventually add some more features, like a chpasswd-style script, and features that ensure all the users with hashedPasswordFile have a password set to help with bootstrapping, but it's currently pretty barebones. However, it is enough for my personal needs at the moment and so I figure it is a good time to get some more eyes on it. github.com GitHub - Anomalocaridid/hpf-passwd: Manage passwords on NixOS systems that use... Manage passwords on NixOS systems that use `hashedPasswordFile` 1 post - 1 participant Read full topic

## A college student's guide to better digital security

DevFeed: [A college student's guide to better digital security](<https://devfeed.tech/articles/a-college-student-s-guide-to-better-digital-security-1909.md>)

Original publisher: [Read original article](<https://1password.com/blog/college-students-guide-to-better-digital-security>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-07-24T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Digital Security](<https://devfeed.tech/topics/digital-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [digital-security](<https://devfeed.tech/tags/digital-security.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tips-advice](<https://devfeed.tech/tags/tips-advice.md>)

### AI overview

A guide for college students on improving digital security by using strong, unique passwords and a password manager. It explains how password managers can create, remember, and autofill passwords while helping organize logins and data.

### Source excerpt

Do you prefer a short flight or a long drive? Do you have an undiscovered love for esports? Do you look good with bangs and, if not, do you look good in hats? College is the perfect time to learn and discover new things about yourself, in the classroom and beyond. It's also the perfect time to learn how to keep all of that information safe. Starting college means that you're creating and responsible for more data than ever before. You're spinning up new logins for your school accounts, booking your own travel, managing your legal documents, making your own appointments, and maybe even opening your first bank account. Every one of these interactions presents you with a choice: are you going to set up a secure and organized system for managing your logins and data? Or...are you going to keep re-using the same password you've had since middle school? In the moment, it can seem like you're choosing between "secure but a hassle" and "risky but convenient." But that's a false choice, because good security habits actually make your life easier in the long run. (And let's face it, you've probably already wasted enough time trying to remember if your old standby password currently ends in a "1" or an exclamation point.) One more question: what's the best tool to help you get started on your security journey? For once, the answer is simple: it's a password manager. How password managers help college students stay secure Online security depends on using strong, unique passwords for every account. That way, just because your roommate shares your Netflix password with all of their friends, it doesn't mean that your student aid login is at risk as well. Despite this, people still recycle old passwords, even after they've been the victim of an attack. 1Password's research has found that a whopping 76% of people who have been phished still reuse passwords across their accounts. Meanwhile, another recent survey found that 48% of Gen Z admit to using the names of family members or pets

## Strong Customer Authentication (SCA): A Practical Guide for SaaS

DevFeed: [Strong Customer Authentication (SCA): A Practical Guide for SaaS](<https://devfeed.tech/articles/strong-customer-authentication-sca-a-practical-guide-for-saas-10400.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/strong-customer-authentication/>)

Author: Ayush Agarwal

Published: 2026-07-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [conversion](<https://devfeed.tech/tags/conversion.md>), [europe](<https://devfeed.tech/tags/europe.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [payments](<https://devfeed.tech/tags/payments.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>)

### AI overview

A practical guide to Strong Customer Authentication (SCA), explaining PSD2 requirements, two-factor verification, common authentication factors, 3D Secure, exemptions, and the effect of implementation on checkout conversion and fraud liability.

### Source excerpt

Strong Customer Authentication (SCA) is the PSD2 rule requiring two-factor verification on many payments. Learn how SCA works, its exemptions, and how to stay compliant without killing conversion.

## AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)

DevFeed: [AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)](<https://devfeed.tech/articles/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions-pwn-request-july-2026-12890.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions>)

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [AsyncAPI Specification](<https://devfeed.tech/topics/asyncapi.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [asyncapi-supply-chain-attack](<https://devfeed.tech/tags/asyncapi-supply-chain-attack.md>), [chainguard-asyncapi](<https://devfeed.tech/tags/chainguard-asyncapi.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-actions-pwn-request](<https://devfeed.tech/tags/github-actions-pwn-request.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article analyzes a July 14, 2026 supply-chain compromise in which an attacker stole a privileged GitHub personal access token through a misconfigured GitHub Actions workflow and used it to publish five backdoored versions across four AsyncAPI npm packages. The malware activates when a library is loaded by a build or CI job and steals browser passwords, SSH keys, npm and GitHub tokens, cloud credentials, and cryptocurrency wallets while maintaining command-and-control access. It also explains why Chainguard customers were protected and recommends treating affected environments as compromised and rotating credentials.

### Source excerpt

A supply chain attack compromised AsyncAPI npm packages via GitHub Actions. See how Chainguard blocked the malicious releases by design.

## Sign in to Pulumi Cloud with Passkeys

DevFeed: [Sign in to Pulumi Cloud with Passkeys](<https://devfeed.tech/articles/sign-in-to-pulumi-cloud-with-passkeys-19019.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/passkey-support-in-pulumi-cloud/>)

Author: Devon Grove

Published: 2026-07-13T00:00:00Z

Content type: release

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [bitbucket](<https://devfeed.tech/tags/bitbucket.md>), [features](<https://devfeed.tech/tags/features.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [google](<https://devfeed.tech/tags/google.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [product-launches](<https://devfeed.tech/tags/product-launches.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Pulumi Cloud now supports passkeys for users who sign in with an email address and password. Passkeys use device-stored public-key credentials and WebAuthn, while identity-provider sign-in flows remain unchanged.

### Source excerpt

Pulumi Cloud now supports passkeys for users who sign in with email and password. Select a button, approve with Touch ID, Face ID, Windows Hello, or your hardware key, and you're signed in. A passkey is a public-key credential stored on your device: your phone, your laptop, a hardware key (YubiKey, Google Titan, etc.), or your password manager can all function as the authenticator. When you sign in, your device authenticates you locally and signs a challenge from Pulumi Cloud with the private key. The private key stays on your device -- Pulumi Cloud never sees or stores it. Passkeys are built on the WebAuthn standard, so they're already supported on every major browser and operating system. Who this is for This release applies to users who sign in to Pulumi Cloud with an email address and password. If you sign in through an identity provider (IdP), such as GitHub OAuth, GitLab, Bitbucket, Google, or your organization's SAML SSO, your existing flow is unchanged. Why passkeys Passwords have always been the weakest link in account security. Since they are shared secrets, they are vulnerable to phishing attacks, and every place you type one is a place that can be impersonated or a data store that can be leaked. Passkeys swap that out for a per-site key pair that lives on your device: Phishing-resistant by design. A passkey is bound to the exact origin it was registered for. A look-alike domain can't trigger your authenticator. Synced across your devices. Apple iCloud Keychain, Google Password Manager, 1Password, Dashlane, Bitwarden: most credential managers now sync passkeys end-to-end-encrypted to every device you've signed in on. Discoverable. Pulumi Cloud doesn't need to know which user you are before you authenticate. Just select "Sign in with a passkey" and your device offers the right credential. Nothing to remember. A passkey lives on your device. There's no string to memorize, and no sensitive credential stored by us. Setting up a passkey The next time you sign i

## How IT can reduce credential risk across every department

DevFeed: [How IT can reduce credential risk across every department](<https://devfeed.tech/articles/how-it-can-reduce-credential-risk-across-every-department-1911.md>)

Original publisher: [Read original article](<https://1password.com/blog/credential-risk-across-departments>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [webinars](<https://devfeed.tech/tags/webinars.md>)

### AI overview

A 1Password webinar recap about credential sprawl across departments. It argues that AI agents and AI tools increase the risk of exposing passwords, API keys, tokens, and other developer secrets, creating a need for IT and security oversight.

### Source excerpt

Note __This blog is a recap of 1Password's recent webinar, "The credential sprawl tour: Is your department leaking secrets?" [Head here](https://1password.com/webinars/secure-every-credential) to watch the complete webinar recording.__ Credential sprawl has long been an issue IT and security teams have had to grapple with, and solutions like single-sign-on (SSO) have never been able to contain it completely. Now, AI is accelerating the problem. AI agents need access to credentials at an unprecedented scale, leaving IT and security teams struggling even more to ensure that every credential, across every department, is secure. These issues were the focus of 1Password's recent webinar: "The credential sprawl tour: Is your department leaking secrets?" During the webinar, Sebastian Cevallos, Senior Product Marketing Manager, and Graham McKelvie, Solutions Engineer, explored how 1Password's solutions can help IT and security teams secure and govern these unapproved or unmanaged credentials. Key takeaways from the webinar: AI didn't create credential sprawl, but it's accelerating it Teams like product, marketing, and finance all have complex needs when it comes to managing credential sprawl Third-party contractors and vendors are their own challenge, and overprivileged access poses increasing risk to security 1Password provides IT and security teams with the tools they need to gain oversight and governance over all of the credentials that exist outside SSO Read on for an in-depth exploration of the webinar's key themes. Password and secrets sprawl across every department The webinar provided a department-by-department overview of how credential sprawl proliferates across teams and roles. Product: Developer secrets are used across departments AI is dramatically changing how teams manage developer secrets. As McKelvie explained, "The challenge isn't just managing passwords anymore. It's managing every identity, credential, API key, tokens, and all of the secrets that are pow

## Don't bring exposed developer credentials to Black Hat

DevFeed: [Don't bring exposed developer credentials to Black Hat](<https://devfeed.tech/articles/don-t-bring-exposed-developer-credentials-to-black-hat-1914.md>)

Original publisher: [Read original article](<https://1password.com/blog/developer-credential-security-black-hat-2026>)

Author: info@1password.com (Eric Eddy)

Published: 2026-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [mount](<https://devfeed.tech/topics/mount.md>), [Go](<https://devfeed.tech/topics/go.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Python](<https://devfeed.tech/topics/python.md>), [make](<https://devfeed.tech/topics/make.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [developers](<https://devfeed.tech/tags/developers.md>), [events](<https://devfeed.tech/tags/events.md>), [go](<https://devfeed.tech/tags/go.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [leaderboard](<https://devfeed.tech/tags/leaderboard.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [python](<https://devfeed.tech/tags/python.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article urges developers attending Black Hat to secure locally stored credentials before the conference. It discusses exposed AWS credentials and SSH keys, plaintext secrets, outdated cryptography, and 1Password tools for discovering, securing, and accessing credentials. It also describes mounted environment variables, CLI and SDK integrations, developer demonstrations, and a credential-sprawl challenge.

### Source excerpt

Black Hat is where the security industry gathers to compare notes on current cybersecurity topics. It brings together a diverse group of security experts, from C-suite executives to black-hat hackers. Some attendees see it as a target-rich environment for testing their latest hacks. Many hackers and supply chain attacks rely on the fact that local credentials are stored in predictable locations with standardized file names, in clear text. For example, AWS credentials usually live in ~/.aws/credentials because the CLI writes them there by default. SSH keys live in ~/.ssh. 1Password developer tools can secure these credentials. It's never a bad time to secure locally-stored developer credentials, but if you're attending Black Hat, this might be an especially good time. Secure your credentials in 1Password before the conference, and find us at the booth to get an exclusive sticker. Find and secure SSH keys Developer watchtower discovers SSH keys that are stored in plaintext or use outdated cryptography. Follow the documentation to discover and secure your local SSH keys, which you can then access from the terminal using biometrics, just the same way you do for your passwords. Secure environment variables (Beta) 1Password Environments make your Environment's variables available via locally mounted .env files, without writing your credentials to disk. You can securely share them with team members and access them programmatically in your terminal via our CLI or via our SDK in Go, JavaScript, or Python integrations. Follow the documentation to secure and mount your environment variables. Find us at booth 4735 Located in the main exhibit hall near the Bayside C escalators. If you're attending the conference please come say hello, pick up some stickers, and ask us all your questions about 1Password developer tools! Play our developer challenge, Credential Sprawl Capture the Flag to win exclusive swag and get your name on our leaderboard. We'll be running live demos and havin

## Inside an AI coal mine security camera network powered by plaintext passwords

DevFeed: [Inside an AI coal mine security camera network powered by plaintext passwords](<https://devfeed.tech/articles/inside-an-ai-coal-mine-security-camera-network-powered-by-plaintext-passwords-32622.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/07/08/coal-india-camera-hack/>)

Author: Eaton

Published: 2026-07-08T17:07:38Z

Content type: opinion

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [breach](<https://devfeed.tech/tags/breach.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This security write-up examines Coal India's Project DigiCoal camera-monitoring platform, developed by DeepSight AI Labs and Accenture. It reports that the RPI Dashboard exposed user accounts and plaintext, weak, duplicated passwords through an unauthenticated API. The article also describes bypassing client-side access controls to view camera alerts and feeds across seven coal mines.

### Source excerpt

Coal India's intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.

## Inside the inbox: Why cybercriminals want to break into your email account

DevFeed: [Inside the inbox: Why cybercriminals want to break into your email account](<https://devfeed.tech/articles/inside-the-inbox-why-cybercriminals-want-to-break-into-your-email-account-8354.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/>)

Author: Phil Muncaster

Published: 2026-06-29T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [data](<https://devfeed.tech/topics/data.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [identity](<https://devfeed.tech/tags/identity.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains why email inboxes are high-value targets for cybercriminals. Access can enable password resets, interception of one-time passcodes, persistent forwarding rules, misuse of connected sessions and apps, phishing, identity fraud, blackmail, and access to corporate systems and customer data.

### Source excerpt

Your inbox is an identity system all of its own: whoever owns it may own a lot more

[Next page](<https://devfeed.tech/tags/passwords.md?cursor=WyIyMDI2LTA2LTI5VDA4OjUwOjAwKzAwOjAwIiwgIjk0YTc4MDZiLTE1Y2UtNDQzYy1hNGMxLTcxZWJlYmJiMTc3YSJd>)