Web sign-in has moved to secure, HTTP-only cookies, which means your login is never readable by scripts in the browser. The phone app stores its login in the device's secure keychain.
The server runtime was upgraded to a current long-term-support version and all known dependency advisories were cleared. Sign-in, password reset and two-factor screens now have tighter rate limits.
As always, we do not publish the detail of security work here.