#LastPass

Xavier «X» Santolaria :verified_paw: :donor:0x58@infosec.exchange
2026-01-24

🔥 Latest issue of my curated #cybersecurity and #infosec list of resources for week #04/2026 is out!

→ It includes the following and much more:

🎣 📩 LastPass warns of a #phishing campaign pretending to be #LastPass;

🇺🇸 🎽 Under Armour investing #breach;

🇯🇴 📲 Jordanian authorities used #Cellebrite phone-cracking tools to extract data from activists’ phones without consent;

🇮🇪 👀 #Ireland plans a new law to let police use #spyware;

💬 🔐 @moxie launched #Confer, a #ChatGPT-like service built to protect user #privacy;

💥 Attackers exploiting critical Fortinet #FortiCloud flaw;

🇷🇺 🇵🇱 Russian government hackers likely tried to knock out parts of Poland’s power grid;

--

👉 NEVER MISS my curations and updates on information security and cybersecurity news and challenges 📨 Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

Teddy / Domingo (🇨🇵/🇬🇧)TeddyTheBest@framapiaf.org
2026-01-23

#Phishing Campaign Zeroes in on #LastPass Customers. The bait incudes plausible subject lines and credible messages, most likely thanks to attackers' use of large language models to craft them.
darkreading.com/application-se
#passwords #security

2026-01-23

Is there some reason LastPass Enterprise only recognizes your Master Password for a limited amount of time and once that time has elapsed if you're somehow logged out it'll never recognize it again?

#lastpass

2026-01-22

🚨 LastPass phishing campaign uncovered
Fake “urgent backup” emails redirect users to malicious sites designed to steal master passwords — granting full vault access.
LastPass confirms it never requests this via email.

🔗 technadu.com/lastpass-backup-p

Thoughts on improving phishing resilience for password manager users?

#Infosec #Phishing #LastPass #CredentialTheft

LastPass Backup Phishing Campaign Exposed: Deceptive Requests Target Password Vaults

Tja, wenn doch nur jemand davor gewarnt hätte…

…einen passwortmänätscher zu benutzen, der die datenbanken für die passwörter zentral im internetz speichert. Wenn die krypto gut genug ist, um angreifer abzuwehren, dann gibt es eben plumpe phishing-angriffe, auf die auch immer wieder leute reinfallen.

Nehmt einfach einen passwortmänätscher, bei dem ihr selbst wisst, wo die daten rumliegen und bei dem ihr niemals auch nur auf die idee kommt, das hauptpasswort irgendwo auf einer komischen webseit einzugeben. Klar, da muss man sich auch selbst um datensicherung und synkronisazjon zwischen verschiedenen geräten kümmern. Aber das ist nicht so schwierig. Datenzäpfchen und speicherkarten sind billig und einfach zu benutzen.

#LastPass #Passwort #Passwortmanager #Phishing #Security

2026-01-22

I would hope I don’t need to let most people know, but…

Lastpass phishing - and this might be expensive for the unwary

Remember, following liks in emails can be dangerous - following links to shortened URLS is silly

theregister.com/2026/01/21/las

#LastPass #Phishing #Security #IT

2026-01-22
TugaTech 🖥️tugatech@masto.pt
2026-01-22
2026-01-22

📢 Alerte: campagne de phishing imitant une maintenance LastPass demandant une sauvegarde sous 24 h
📝 Selon BleepingComputer, LastPass met en garde contre une nouvel...
📖 cyberveille : cyberveille.ch/posts/2026-01-2
🌐 source : bleepingcomputer.com/news/secu
#LastPass #ingénierie_sociale #Cyberveille

Aaron Toponce ⚛️:debian:atoponce@fosstodon.org
2026-01-21

New phishing attack targeting #LastPass customers. The phish is asking them to backup their vault before LastPass undergoes server maintenance.

blog.lastpass.com/posts/new-ph

#passwords

gtbarrygtbarry
2026-01-21

@BleepingComputer Wouldn't it just be easier for hackers to assume that anyone idiotic enough to trust for their password management needs uses "password" or "123456" for their master password?

Esparta :ruby:esparta@ruby.social
2026-01-13

I just learnt that #1Password dunks in #LastPass if you migrate your vault

This is the first time a retrieve one of the secrets... and I was received with a big red square that reads:

> Imported from LastPass

> LastPass suffered a data breach in August 2022. Change your password to keep your account safe.

- Change password on website
- Ignore

An screenshot of my #1Password, which our $CURRENT_EMPLOYER just recently migrated from #LastPass

in big red square it reads:

Imported from LastPass

LastPass suffered a data breach in August 2022. Change your password to keep your account safe.

< two buttons>

- Change password on website
- Ignore
Jonu ☮️ 🕉️jonu@norden.social
2026-01-11

Yeah, #lastpass forderte den Zugriff auf Web-Seiten Verlauf. Nun war der Moment gekommen - Wechsel: #keepassXC mit dem Vorteil, auch auf dem Handy. 10 € gehen auf jeden Fall jährlich an die Entwickler.

Jetzt wird das Add-On gelöscht.

PS: Ist es möglich zu einigen - welcher Tag gilt denn nun?

#dit #IDIT #di.day #DigitalIndependenceDay #diday #dut #DiDit #DUTgemacht #DID

@allpoints I don't think #LastPass should be trusted anymore, see en.wikipedia.org/wiki/LastPass for details.

I think #Bitwarden and/or #1Password are much better. Both have add-ons for Firefox.

gtbarrygtbarry
2026-01-09

Historic LastPass breach enabling cryptocurrency theft, investigation reveals

The data breach incident at LastPass, which happened more than three years ago, is still enabling cryptocurrency theft. Cybercriminals managed to steal approximately $35 million to date by cracking stolen LastPass vaults

techradar.com/pro/security/his

2026-01-09

Just got a notice that the LastPass plug-in on Firefox wants to access more info than it needs just to supply a password. It could be innocuous but it feels like they've begun user tracking.

What are folks using for password management? preferably something with a Firefox/Waterfox plugin.

#Security #Firefox #Waterfox #LastPass

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst