Hackers Had Access to LastPass’s Development Systems for Four Days

Teilen:

Password management solution LastPass shared more details pertaining to the security incident last month, disclosing that the threat actor had access to its systems for a four-day period in August 2022.

“There is no evidence of any threat actor activity beyond the established timeline,” LastPass CEO Karim Toubba sagte in an update shared on September 15, adding, “there is no evidence that this incident involved any access to customer data or encrypted password vaults.”

LastPass in late August revealed that a breach targeting its development environment resulted in the theft of some of its source code and technical information, although no further specifics were offered.

 

The company, which said it completed the probe into the hack in partnership with incident response firm Mandiant, noted the access was achieved using a developer’s compromised endpoint.

While the exact method of initial entry remains “inconclusive,” LastPass noted the adversary abused the persistent access to “impersonate the developer” after the victim had been authenticated using multi-factor authentication.

The company reiterated that despite the unauthorized access, the attacker failed to obtain any sensitive customer data owing to the system design and zero trust controls put in place to prevent such incidents.

This includes the complete separation of development and production environments and its own inability to access customers’ password vaults without the master password set by the users.

“Without the master password, it is not possible for anyone other than the owner of a vault to decrypt vault data,” Toubba pointed out.

Additionally, it also said it conducted source code integrity checks to look for any signs of poisoning and that developers do not possess the requisite permissions to push source code directly from the development environment into production.

Last but not least, LastPass noted that it has engaged the services of a “leading” cybersecurity firm to enhance its source code safety practices and that it has deployed additional endpoint security guardrails to better detect and prevent attacks aimed at its systems.

https://thehackernews.com/2022/09/hackers-had-access-to-lastpasss.html?

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:52 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
broken clouds
Luftfeuchtigkeit: 90 %
Druck: 1013 mb
Wind: 10 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 5 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 1 mm 100% 13 mph 92 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 13°°C 1 mm 100% 10 mph 90 % 1013 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,255.86
-2.24%
Ethereum(ETH)
€2,242.40
-5.30%
Fesseln(USDT)
€0.88
0.02%
XRP(XRP)
€2.06
-4.53%
Solana(SOL)
€154.01
-3.84%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.200719
-7.53%
Shiba Inu(SHIB)
€0.000012
-7.05%
Pepe(PEPE)
€0.000012
-10.71%
Peanut das Eichhörnchen(PNUT)
€0.306300
-7.81%
Nach oben scrollen