Advertisement Banner
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result

No products in the cart.

  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
No Result
View All Result
Home GADGET

LastPass says hackers broke into an employee PC to steal the company’s password vault

North Dakota Digital News by North Dakota Digital News
February 28, 2023
in GADGET
36 3
0
LastPass says hackers broke into an employee PC to steal the company’s password vault
32
SHARES
356
VIEWS
Share on TwitterShare on Facebook


LastPass has posted an update on its investigation regarding a couple of security incidents that took place last year, and they’re sounding graver than previously thought. Apparently, the bad actors involved in those incidents also infiltrated a company DevOps engineer’s home computer by exploiting a third-party media software package. They implanted a keylogger into the software, which they then used to capture the engineer’s master password for an account with access to the LastPass corporate vault. After they got in, they exported the vault’s entries and shared folders that contained decryption keys needed to unlock cloud-based Amazon S3 buckets with customer vault backups.

This latest update in LastPass’ investigation gives us a clearer picture of how the two security breach incidents it went through last year were connected. If you’ll recall, LastPass revealed in August 2022 that an “unauthorized party” gained entry into its system. While the first incident ended on August 12th, the company said in its new announcement that the threat actors were “actively engaged in a new series of reconnaissance, enumeration, and exfiltration activities aligned to the cloud storage environment spanning from August 12th, 2022 to October 26th, 2022.”

When the company announced the second security breach in December, it said the bad actors used information obtained from the first incident to get into its cloud service. It also admitted that the hackers made off with a bunch of sensitive information, including its Amazon S3 buckets. To be able to access the data saved in those buckets, the hackers needed decryption keys saved in “highly restricted set of shared folders in a LastPass password manager vault.” That’s why the bad actors targeted one of the four DevOps engineers who had access to the keys needed to unlock the company’s cloud storage. 

In a support document (PDF) the company released (via BleepingComputer), it detailed the data accessed by the threat actors during the two incidents. Apparently, the cloud-based backups accessed during the second breach included “API secrets, third-party integration secrets, customer metadata and backups of all customer vault data.” The company insisted that all sensitive customer vault data aside from some exceptions “can only be decrypted with a unique encryption key derived from each user’s master password.” The company added that it doesn’t store users’ master passwords. LastPass also detailed the steps it has taken to strengthen its defenses going forward, including revising its threat detection and making “a multi-million-dollar allocation to enhance [its] investment in security across people, processes, and technology.”

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission. All prices are correct at the time of publishing.



Source link

Tweet8Share13Share3Share
Previous Post

C4R announced North American expansion under Atriny Group brand. – Retail Dive

Next Post

Xiaomi 13 Pro launched in India for INR 79,999

North Dakota Digital News

North Dakota Digital News

Next Post
Xiaomi 13 Pro launched in India for INR 79,999

Xiaomi 13 Pro launched in India for INR 79,999

Discussion about this post

Bismarck
◉
7°
Clear
7:24 am6:26 pm CST
Feels like: -4°F
Wind: 6mph ENE
Humidity: 80%
Pressure: 29.85"Hg
UV index: 0
WedThuFri
12/0°F
28/18°F
36/12°F
Weather forecast Bismarck, North Dakota ▸
Elden Ring expansion Shadow of the Erdtree is officially in development
TECH

Elden Ring expansion Shadow of the Erdtree is officially in development

by North Dakota Digital News
February 28, 2023
Everything About His Twins – Hollywood Life
ENTERTAINMENT

Everything About His Twins – Hollywood Life

by North Dakota Digital News
February 28, 2023
A Surprising Way to Help Kids Open Up About Feelings
LIFESTYLE

A Surprising Way to Help Kids Open Up About Feelings

by North Dakota Digital News
February 28, 2023
Benson Hill Announces Preliminary Unaudited 2022 Results and … – Business Wire
PRESS RELEASE

MultiPlan Announces $100 Million Share Repurchase Program – Business Wire

by North Dakota Digital News
February 28, 2023
3 Real Winning Deals in 2023 (and Where You Can Find Them!)
REAL ESTATE

3 Real Winning Deals in 2023 (and Where You Can Find Them!)

by North Dakota Digital News
February 28, 2023
Pending Home Sales Rose In January — But Gains Are Unlikely To Last
SCIENCE

Pending Home Sales Rose In January — But Gains Are Unlikely To Last

by North Dakota Digital News
February 28, 2023
Xiaomi 13 Pro launched in India for INR 79,999
MOBILE

Xiaomi 13 Pro launched in India for INR 79,999

by North Dakota Digital News
February 28, 2023
LastPass says hackers broke into an employee PC to steal the company’s password vault
GADGET

LastPass says hackers broke into an employee PC to steal the company’s password vault

by North Dakota Digital News
February 28, 2023
Benson Hill Announces Preliminary Unaudited 2022 Results and … – Business Wire
PRESS RELEASE

C4R announced North American expansion under Atriny Group brand. – Retail Dive

by North Dakota Digital News
February 28, 2023
APPS

Join Us In The 'Zapable Agency Apps' Launch. Over $15,000+ Of Cash Prizes, $248.50 Commission/Sale

by North Dakota Digital News
February 28, 2023
10 Companies That Hire Part-Time Proofreaders and Editors
MONEY

10 Companies That Hire Part-Time Proofreaders and Editors

by North Dakota Digital News
February 28, 2023
SK Telecom GAAP EPS of KRW1147.00, revenue of KRW4290B
MARKET

Diamond Estates Wines & Spirits reports Q3 results

by North Dakota Digital News
February 28, 2023

About Us

North Dakota Digital News

Category

  • APPS
  • ARTS & THEATER
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SPORTS
  • TECH
  • TRAVEL
TECH

Elden Ring expansion Shadow of the Erdtree is officially in development

February 28, 2023
ENTERTAINMENT

Everything About His Twins – Hollywood Life

February 28, 2023
LIFESTYLE

A Surprising Way to Help Kids Open Up About Feelings

February 28, 2023

© 2022 northdakotadigitalnews.com

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

© 2022 northdakotadigitalnews.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In