▲ | dewey 3 days ago | ||||||||||||||||||||||||||||||||||||||||
What do you mean with “last pass got hacked through plex”? | |||||||||||||||||||||||||||||||||||||||||
▲ | tough 3 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||
The LastPass breach was indeed linked to a vulnerability in Plex Media Server. Attackers exploited an unpatched version of Plex on a LastPass DevOps engineer’s personal computer, enabling them to install keylogger malware. This allowed them to capture the engineer’s master password after multi-factor authentication, granting access to sensitive corporate vaults. Notably, the Plex vulnerability had been patched in May 2020—approximately 75 versions prior to the breach. The compromise occurred because the engineer hadn’t updated their Plex software. While the flaw was in Plex, the breach underscores the critical importance of timely software updates and robust security practices. https://www.wired.com/story/lastpass-engineer-breach-securit... | |||||||||||||||||||||||||||||||||||||||||
|