Comment by qwertox
6 hours ago
> I'm pretty sure 99% of the people on exposed have already had their
Right, but LastPass is a company that wants to make you believe that you can trust them with some of your most important assets.
--
Probably related to this:
https://www.bleepingcomputer.com/news/security/lastpass-conf...
“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” LastPass says.
"We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.”
“The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”
That's a npm supply chain attack style but next level for the Enterprise game: hack one and get access to everything of all of them since they are all unrestricted connected and with each other.
And then they force us to install cloudstrike, antiviruses and client side monitoring because "us are the security problem".