Security News

LastPass breach: Hacker accessed corporate vault by compromising senior developer’s home PC
2023-02-28 12:16

LastPass is, once again, telling customers about a security incident related to the August 2022 breach of its development environment and subsequent unauthorized access to the company's third-party cloud storage service that hosted backups: "The threat actor leveraged information stolen during the first incident, information available from a third-party data breach, and a vulnerability in a third-party media software package to launch a coordinated second attack." The second incident went initially unnoticed, LastPass says, the tactics, techniques, and procedures and the indicators of compromise of the second incident "Were not consistent with those of the first." It was only later determined that the two incidents were related.

LastPass Reveals Second Attack Resulting in Breach of Encrypted Password Vaults
2023-02-28 06:16

LastPass, which in December 2022 disclosed a severe data breach that allowed threat actors to access encrypted password vaults, said it happened as a result of the same adversary launching a second attack on its systems. "The threat actor leveraged information stolen during the first incident, information available from a third-party data breach, and a vulnerability in a third-party media software package to launch a coordinated second attack," the password management service said.

LastPass: DevOps engineer hacked to steal password vault data in 2022 breach
2023-02-28 01:40

LastPass disclosed a breach in December where threat actors stole partially encrypted password vault data and customer information. "The threat actor was able to capture the employee's master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer's LastPass corporate vault," reads a new security advisory published today.

LastPass Parent Company GoTo Suffers Data Breach, Customers' Backups Compromised
2023-01-25 07:43

LastPass-owner GoTo on Tuesday disclosed that unidentified threat actors were able to steal encrypted backups of some customers' data along with an encryption key for some of those backups in a November 2022 incident."The affected information, which varies by product, may include account usernames, salted and hashed passwords, a portion of multi-factor Authentication settings, as well as some product settings and licensing information," GoTo's Paddy Srinivasan said.

For password protection, dump LastPass for open source Bitwarden
2023-01-16 11:30

Opinion For better or worse, we still need passwords, and to protect and organize them, I recommend the open source Bitwarden password manager. LastPass is perhaps the world's most popular password manager.

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
2023-01-05 17:52

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all. Actually your passwords were encrypted, but the websites and the web services and an unstated list of other stuff that you stored, well, that *wasn't* encrypted.

Mitigate the LastPass Attack Surface in Your Environment with this Free Tool
2023-01-05 10:51

As often occurs, we are at a security limbo - on the one hand, as LastPass has noted, users who followed LastPass best practices would be exposed to practically zero to extremely low risk. To assist them throughout this challenging time, Browser Security solution LayerX has launched a free offering of its platform, enabling security teams to gain visibility into all browsers on which the LastPass extension is installed and mitigate the potential impacts of the LastPass breach on their environments by informing vulnerable users and require them to implement MFA on their accounts and if required, roll out a dedicated Master Password reset procedure to eliminate adversaries' abilities to leverage a compromised Master Password for malicious access.

LastPass Breach
2022-12-26 12:06

The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data. As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass.

Week in review: LastPass breach disaster, online tracking via UID smuggling, ransomware in 2023
2022-12-25 09:30

LastPass says attackers got users' info and password vault dataThe information couldn't come at a worst time, as businesses are winding down their activities and employees and users are thick in the midst of last-minute preparations for end-of-year holidays. New Microsoft Exchange exploit chain lets ransomware attackers inRansomware-wielding attackers are using a new exploit chain that includes one of the ProxyNotShell vulnerabilities to achieve remote code execution on Microsoft Exchange servers.

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…
2022-12-23 19:58

We have seen no evidence that this incident involved any access to customer data or encrypted password vaults. Although the threat actor was able to access the Development environment, our system design and controls prevented the threat actor from accessing any customer data or encrypted password vaults.