LastPass notifies users of yet another data breach

LastPass suffered another data breach through third-party vendor Klue, exposing customer contact information and CRM data, though encrypted password vaults remained secure. This incident is the third major security event for LastPass in recent years, raising critical questions about vendor risk management and the company's security posture that CIOs must address in their password management strategy and third-party governance frameworks. The breach underscores the need for organizations to audit their dependency on LastPass and implement compensating controls such as enhanced monitoring for phishing attacks using the exposed contact information.

Marcus Mendes9to5Mac2 min read1 views
Read full article
LastPass notifies users of yet another data breach
LastPass users are once again being warned about stolen personal data, though this time the breach happened through one of the company’s outside partners. Here are the details.