Breaking News

CASIO introduces a new limited edition Hammered heritage model, the New MRG-B5000HT Introducing the Game-Changing MINISFORUM G1 Pro PlayStation Plus Monthly Games for December 2025 SSSTC Launches 16TB Enterprise SATA SSD with Breakthrough IOPS Performance Lexar Unveils Industry’s First AI Storage Core for Next Generation Edge AI Devices

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

LastPass Corrects Bug That Could Potentially Expose Millions of Users to ‘Last Password’ Credential Leak

LastPass Corrects Bug That Could Potentially Expose Millions of Users to ‘Last Password’ Credential Leak

Enterprise & IT Sep 16,2019 0

Google Project Zero has found a credential leaking vulnerability in the LastPass password manager.

Security analysts at Google's Project Zero team typically report to the vendor concerned and start a 90-day countdown for a fix to be issued before full public disclosure is made.

Project Zero disclosed that a security vulnerability left some of those 16 million users exposed to the risk of credential compromise as LastPass could leak the last password used to any website visited.

LastPass is in the security business, being one of the most popular password management solutions with more than 16 million users, including 58,000 businesses.

In a tweet, Google Project Zero analyst Tavis Ormandy stated that "LastPass could leak the last used credentials due to a cache not being updated," adding "this was because you can bypass the tab credential cache being populated by including the login form in an unexpected way!"

Google's report revealed "a limited set of circumstances on specific browser extensions that could potentially allow an attacker to create a clickjacking scenario," Ferenc Kun, the security engineering manager for LastPass.

No user action is required and your LastPass browser extension will update automatically, according to Kun.

Additionally, while any potential exposure due to the bug was limited to specific browsers (Chrome and Opera), as a precaution, LastPass says it has deployed the update to all browsers.

As a reminder LastPass continues to recommend the following general best practices for added online security:

  • Beware of phishing attacks. Do not click on links from people you don’t know, or that seem out of character from your trusted contacts and companies.
  • Always enable MFA for LastPass and other services like your bank, email, Twitter, Facebook, etc. Adding additional layers of authentication remains the most effective way to protect your account.
  • Never reuse your LastPass master password and never disclose it to anyone, including us.
  • Use different, unique passwords for every online account.
  • Keep your computer malware-free by running antivirus with the latest detection patterns and keeping your software up-to-date.

Tags: bugsCybersecurityLastPass
Previous Post
OnePlus 7T to Debut October 10
Next Post
Volkswagen to Invest $9 Billion in Software

Related Posts

  • Intel Confirms "Thunderspy" Risk in Thuerbolt Devices

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Apple Says 'No Evidence' iPhone Mail Bug Used Against Consumers

  • Malwarebytes Introduces VPN Service

  • Google Says State-backed Hackers Use Coronavirus For Phishing Attacks

  • Apple to Patch Serious iOS Vulnerability

  • Apple is The Most Imitated Brand For Phishing in Q1 2020

  • Microsoft Shares Threat Intelligence During Global Crisis

Latest News

CASIO introduces a new limited edition Hammered heritage model, the New MRG-B5000HT
Consumer Electronics

CASIO introduces a new limited edition Hammered heritage model, the New MRG-B5000HT

Introducing the Game-Changing MINISFORUM G1 Pro
Enterprise & IT

Introducing the Game-Changing MINISFORUM G1 Pro

PlayStation Plus Monthly Games for December 2025
Gaming

PlayStation Plus Monthly Games for December 2025

SSSTC Launches 16TB Enterprise SATA SSD with Breakthrough IOPS Performance
Enterprise & IT

SSSTC Launches 16TB Enterprise SATA SSD with Breakthrough IOPS Performance

Lexar Unveils Industry’s First AI Storage Core for Next Generation Edge AI Devices
Enterprise & IT

Lexar Unveils Industry’s First AI Storage Core for Next Generation Edge AI Devices

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed