Just in:
Dubai Advances Autonomous Taxi Services with Global Tech Partnerships // EU Antitrust Decision on ADNOC’s Covestro Acquisition Expected by May 12 // Proton Enhances Drive and Docs Services Amid Linux User Anticipation // HKPC Achieves Remarkable Accomplishments at Hannover Messe 2025 // Google Addresses Pixel Weather Widget’s Outdated Forecasts // Damac’s Edgnex Data Centers Acquires Finland’s Hyperco to Expand Nordic Presence // US Tariffs Threaten India’s Gems and Jewellery Exports // Galaxy Macau™ Presents: ANDREA BOCELLI Live in Concert – A Soul-Stirring Spectacle // CPI General Secretary D Raja Underlines Principled Unity Of All Communists To Fight RSS-BJP // Trump’s 26% Tariff Escalates US-India Trade Tensions // Trump’s Sweeping Tariffs Set to Reshape Global Trade Dynamics // Eric Trump Ventures into Bitcoin Mining Following Bank Account Closures // CoinList Reopens U.S. Token Sales Amid Eased Regulatory Climate // e& PPF Telecom Group Completes €825 Million Acquisition of Serbia Broadband // Aspire Secures Capital Markets Services Licence from Monetary Authority of Singapore // Absa Group to Establish Dubai Office Amid Strengthening Africa-Gulf Investment Ties // Kraken Bolsters Canadian Presence with Regulatory Approval and Leadership Appointment // Market cycles: leveraging seasonal trends with Octa Broker // Majority of CIOs Overspend on Cloud Budgets, Survey Reveals // PolyU establishes Otto Poon Research Institute for Climate-Resilient Infrastructure with support from Otto Poon Charitable Foundation //

LastPass Updates Security After Vulnerability Was Exposed By A Researcher


LastPass, a known password manager, has revealed security flaws in its browser extensions. The company is already patching the vulnerability, which was revealed by a security researcher this week. 
( LastPass )

ADVERTISEMENT

What is worse than a forgotten password? A stolen one.

Password manager LastPass is in hot water this week as security flaws were discovered in its web browser extension. On March 26, Google security researcher Tavis Ormandy exposed a client-side vulnerability in LastPass that he found in Google Chrome. LastPass acknowledged the problem and vowed to address it.

Cybersecurity has been a hot topic this March. On a major scale, WikiLeaks leaked documents on CIA spying. On a lesser degree, Google Allo was found out to reveal your recent browsing history.

A ‘Unique And Highly Sophisticated’ Attack

Google Project Zero security researcher Tavis Ormandy revealed via Twitter the client-side vulnerability he discovered in a LastPass browser extension and sent the company a report. As per Project Zero’s policy, LastPass now has 90 days to fix the issue before Google discloses the vulnerability details. LastPass immediately sprang into action to address this security flaw.

LastPass acknowledged the breach and calls it a “unique and highly sophisticated” attack. As protocol and also for security purposes, the company did not reveal the details about the attack.

“We don’t want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties,” wrote LastPass in its official blog.

LastPass also disclosed that a “more detailed post mortem” report will be published once the problem is resolved.

This isn’t the first time that a LastPass vulnerability was exposed by Ormandy. Earlier this March, Ormandy reported two separate flaws in LastPass’ browser add-on. This third vulnerability might take a while according to Ormandy, calling it a “major architectural problem.”

How To Protect LastPass Account

LastPass acknowledged Ormandy’s efforts in helping the company “raise the bar for online security” and vowed to work to become the most secured password manager in the market. As a precaution, it shared tips on how users can protect their accounts from this type of security breach.

One suggestion LastPass shared is using LastPass Vault as a launch pad for password-protected sites. According to LastPass, this is the safest way to access their credentials, which will be the case until the vulnerability is resolved.

Another is Two-Factor Authentication. LastPass suggested to users to do this with their accounts “whenever possible” as most websites offer this option already.

Lastly, the company warned against phishing attacks, cautioning users not to click on suspicious links and advising them to read its phishing primer.




© 2017 Tech Times, All rights reserved. Do not reproduce without permission.

(Via TechTimes)


Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Just in:
EU Antitrust Decision on ADNOC’s Covestro Acquisition Expected by May 12 // Proton Enhances Drive and Docs Services Amid Linux User Anticipation // Kraken Bolsters Canadian Presence with Regulatory Approval and Leadership Appointment // Galaxy Macau™ Presents: ANDREA BOCELLI Live in Concert – A Soul-Stirring Spectacle // Absa Group to Establish Dubai Office Amid Strengthening Africa-Gulf Investment Ties // Brazilian President Seeking Support From China And Russia To Meet Trump’s Threat // Google Addresses Pixel Weather Widget’s Outdated Forecasts // Eric Trump Ventures into Bitcoin Mining Following Bank Account Closures // e& PPF Telecom Group Completes €825 Million Acquisition of Serbia Broadband // Trump’s Sweeping Tariffs Set to Reshape Global Trade Dynamics // CPI General Secretary D Raja Underlines Principled Unity Of All Communists To Fight RSS-BJP // Enviro-Hub Signs LOI to Divest Waste Recycling and Property Units in Strategic Pivot // Galaxy Macau Presents Luxurious Celebration of Renewal at Banyan Tree Macau with Michelin-starred Chef and Bartender from Asia’s 50 Best Bars // HKPC Achieves Remarkable Accomplishments at Hannover Messe 2025 // Checkout.com and Tabby Collaborate to Enhance BNPL Services in UAE and Saudi Arabia // Market cycles: leveraging seasonal trends with Octa Broker // US Tariffs Threaten India’s Gems and Jewellery Exports // Ripple’s RLUSD Stablecoin Enhances Cross-Border Payments and Gains Kraken Listing // Majority of CIOs Overspend on Cloud Budgets, Survey Reveals // Damac’s Edgnex Data Centers Acquires Finland’s Hyperco to Expand Nordic Presence //