<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6a8.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--rotating_light" style="height:23px;width:auto;vertical-align:middle" title="🚨" alt="🚨" /> If you use Bitwarden, please immediately read: <a href="https://socket.dev/blog/bitwarden-cli-compromised" rel="nofollow noopener"><span>https://</span><span>socket.dev/blog/bitwarden-cli-</span><span>compromised</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/91ea1d57-d127-4a37-8c85-a78d6ec94492/if-you-use-bitwarden-please-immediately-read-https-socket.dev-blog-bitwarden-cli-compromised</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:46:02 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/91ea1d57-d127-4a37-8c85-a78d6ec94492.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Apr 2026 16:21:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 18:24:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/shansterable%40ohai.social">@<span>shansterable</span></a></span> you're welcome, I'm still working on getting mine to use it!</p>]]></description><link>https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455416805380047</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455416805380047</guid><dc:creator><![CDATA[odaeus@social.vivaldi.net]]></dc:creator><pubDate>Thu, 23 Apr 2026 18:24:00 GMT</pubDate></item><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 18:12:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/odaeus%40social.vivaldi.net">@<span>Odaeus</span></a></span> <br />Thank you. My husband uses Bitwarden and I was worried. </p><p>Especially since it took me years to convince him to use a password vault because he doesn't trust them.</p>]]></description><link>https://board.circlewithadot.net/post/https://ohai.social/users/shansterable/statuses/116455371864864237</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ohai.social/users/shansterable/statuses/116455371864864237</guid><dc:creator><![CDATA[shansterable@ohai.social]]></dc:creator><pubDate>Thu, 23 Apr 2026 18:12:34 GMT</pubDate></item><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 17:38:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/shansterable%40ohai.social">@<span>shansterable</span></a></span> <span><a href="/user/thomasfuchs%40hachyderm.io">@<span>thomasfuchs</span></a></span> in this case, "Bitwarden CLI" is the name of the product from Bitwarden that was compromised. The message should be that if you don't know what it means you don't need to worry! Relatively few BW users use it.</p><p>Even for those few people who have been compromised by using the infection version, current indications are that their vault was not specifically leaked because of the way the virus works. However, if they are a programmer (likely, given the specialist nature) then they now have a serious issue as it leaks sensitive data that it finds.</p><p>Techies are concerned about this because it is a big red flag around BWs processes and could indicate they have also been compromised internally by their own tool. They say they've found no evidence of this though: <a href="https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127" rel="nofollow noopener"><span>https://</span><span>community.bitwarden.com/t/bitw</span><span>arden-statement-on-checkmarx-supply-chain-incident/96127</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455239806678021</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455239806678021</guid><dc:creator><![CDATA[odaeus@social.vivaldi.net]]></dc:creator><pubDate>Thu, 23 Apr 2026 17:38:59 GMT</pubDate></item><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 17:29:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/thomasfuchs%40hachyderm.io">@<span>thomasfuchs</span></a></span> I'm grateful that the version in Arch is apparently a couple of releases behind... but that was pretty scary for a moment.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/nflamel/statuses/116455202676975454</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/nflamel/statuses/116455202676975454</guid><dc:creator><![CDATA[nflamel@hachyderm.io]]></dc:creator><pubDate>Thu, 23 Apr 2026 17:29:32 GMT</pubDate></item><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 17:28:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/odaeus%40social.vivaldi.net">@<span>Odaeus</span></a></span> <span><a href="/user/thomasfuchs%40hachyderm.io">@<span>thomasfuchs</span></a></span> <br />I agree. I am scouring the article to find out whether passwords have been compromised. Couldn't they just lead with that?</p><p>I had to look up what a "CLI" is. Even after finding the definition, it only made things more confusing. </p><p>By the way, CLI = Command Line Interface, in case that helps anyone besides me. </p><p>I try to do for initialisms and acronyms what alt text does for images.</p>]]></description><link>https://board.circlewithadot.net/post/https://ohai.social/users/shansterable/statuses/116455197351523211</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ohai.social/users/shansterable/statuses/116455197351523211</guid><dc:creator><![CDATA[shansterable@ohai.social]]></dc:creator><pubDate>Thu, 23 Apr 2026 17:28:11 GMT</pubDate></item><item><title><![CDATA[Reply to 🚨 If you use Bitwarden, please immediately read: https:&#x2F;&#x2F;socket.dev&#x2F;blog&#x2F;bitwarden-cli-compromised on Thu, 23 Apr 2026 17:09:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/thomasfuchs%40hachyderm.io">@<span>thomasfuchs</span></a></span> I feel adding "CLI" is a pretty important distinction here so as not to cause undue stress to BW users (of which I am one, including the CLI!). We don't know if they've been further compromised... yet.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455122823227275</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.vivaldi.net/users/Odaeus/statuses/116455122823227275</guid><dc:creator><![CDATA[odaeus@social.vivaldi.net]]></dc:creator><pubDate>Thu, 23 Apr 2026 17:09:14 GMT</pubDate></item></channel></rss>