Bitwarden launched ‘Cupid Vault’, a feature aimed at safer credential sharing by letting free-tier users create a two-person shared vault as an Organization and invite a trusted person via email. The shared vault is isolated from the user’s personal vault, supports revocation of access, and includes a fingerprint phrase verification step intended to reduce adversary-in-the-middle enrollment risks; both members can edit or delete items in the shared collection.
LastPass’s CEO described the company’s ongoing effort to rebuild trust and security culture following the 2022 intrusions, which began with access to parts of the development environment via a compromised developer account and theft of source code/technical data. LastPass said information from that initial compromise enabled subsequent access to customer-related data, including customer account metadata (e.g., names, billing addresses, emails, phone numbers, IP addresses) and a backup copy of encrypted customer vault data, framing the incident as a catalyst for significant security program changes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On February 12, 2026, Bitwarden introduced 'Cupid Vault,' a free two-person shared vault feature for securely sharing passwords via email invitation. The launch included fingerprint-phrase verification to reduce adversary-in-the-middle risks during onboarding.
In a February 2026 interview, LastPass CEO Karim Toubba said the 2022 breach had driven broad changes to people, processes, and technology, and that the company now operates security standards beyond normal expectations as part of its trust-rebuilding effort.
In response to the breach, LastPass invested heavily in rebuilding its security program, including locked-down employee devices, hardware-based authentication, revamped training, a dedicated security team, and ongoing third-party audits and penetration testing.
Following the initial 2022 intrusion, the attacker obtained customer account information and metadata and accessed an encrypted backup of customer vault data. LastPass said this occurred after the intruder acquired a master password stolen from a senior engineer's home computer.
In August 2022, an unauthorized party accessed parts of LastPass's development environment using a compromised developer account and stole source code and technical data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.