Researchers have demonstrated how the leading password managers can leak credentials on Android devices when using the autofill feature with malicious apps. At the Black Hat Europe conference, Ankit Gangwal of the International Institute of Information Technology presented evidence of this vulnerability, coined “AutoSpill”. The researchers have shared findings with Google and affected password managers, with some deferring the issue to Android. Gangwal suggests passwordless authentication using private cryptographic keys as a potential solution.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,