3 ms·
> This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote co
by corncob15 4y ago
> This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault.
Your corporate vault, with all of your database keys, was stored and accessed from someone's personal computer?
> We assisted the DevOps Engineer with hardening the security of their home network and personal resources.
And even after this incident, you let them keep using a personal computer???
This really just reflects incredibly poorly on LastPass's internal security team. I was under considerably more robust endpoint protection policies as a random intern at a legacy Fortune 500.
Edit: I'm quoting from a separate linked blog post here: https://support.lastpass.com/help/incident-2-additional-details-of-the-attack https://support.lastpass.com/help/incident-2-additional-deta...
- MarkSweep 4y agoThe phrase “home computer” does not appear in the blog post. Where are you seeing this? Did they edit the post or did the URL for this story change?
- camgunz 4y agoIt's an earlier update: https://support.lastpass.com/help/incident-2-additional-details-of-the-attack?uuid=dWiqMp06V4pkaMwU0470 https://support.lastpass.com/help/incident-2-additional-deta...
- nickdurfe 4y agoThe words “home computer” appear here - https://support.lastpass.com/help/incident-2-additional-details-of-the-attack https://support.lastpass.com/help/incident-2-additional-deta..., which is linked at the bottom of the Incident 2 Summary from the parent article.