Get the App
SLTechnology News&Howtos  ›  IT Information  › 

LastPass updates security bulletin: an attacker successfully obtains the company's decryption library by hacking into an employee's home computer

Shulou Source: shulou.com Published: 2023-11-24 15:11:22 10月04日 Update

CTOnews.com, February 28 (Xinhua)-- password management tool LastPass announced on Monday that the attacker associated with the previous attack had hacked into an employee's home computer and obtained a cryptographic library (decrypted vault) that only a few corporate developers could use.

It is reported that the attacker attempted to attack LastPass on August 12, 2022, and carried out "a series of new reconnaissance, enumeration and infiltration activities" between 12 and 26.

In the process, the attacker steals valid credentials from a senior DevOps engineer and accesses the contents of the LastPass data vault. The attacker also accessed the shared cloud storage environment through the data vault.

CTOnews.com translates the content of LastPass as follows:

Target the home computer of a DevOps engineer and use vulnerable third-party media packages to implement the attack. The package enables remote code execution and allows threat actors to implant keylogger malware.

After the employee is authenticated through MFA, the threat participant can capture the employee's master password when entering and gain access to the DevOps engineer's LastPass company vault.

Tags: Attacks attackers employees engineering engineers software companies home content passwords data computers software packages threats announcements valid advanced event personnel code Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux Docker Redmi macOS Shulou Tech Info