• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
lastpass hack: engineer's failure to update plex software led to

LastPass Hack: Engineer’s Failure to Update Plex Software Led to Massive Data Breach

You are here: Home / General Cyber Security News / LastPass Hack: Engineer’s Failure to Update Plex Software Led to Massive Data Breach
March 7, 2023

The massive breach at LastPass was the final result of 1 of its engineers failing to update Plex on their dwelling laptop, in what is a sobering reminder of the hazards of failing to continue to keep program up-to-date.

The embattled password management support past week exposed how unidentified actors leveraged facts stolen from an before incident that took put prior to August 12, 2022, alongside with facts “accessible from a 3rd-party data breach and a vulnerability in a third-party media computer software package deal to launch a coordinated second attack” involving August and October 2022.

The intrusion in the end enabled the adversary to steal partly encrypted password vault facts and client information and facts.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The second attack exclusively singled out a single of the 4 DevOps engineers, focusing on their home computer system with a keylogger malware to attain the qualifications and breach the cloud storage setting.

This, in change, is reported to have been built doable by exploiting a approximately three-yr-old now-patched flaw in Plex to attain code execution on the engineer’s personal computer, the streaming media services told The Hacker Information in a statement.

The vulnerability in query is CVE-2020-5741 (CVSS rating: 7.2), a deserialization flaw impacting Plex Media Server on Windows that makes it possible for a remote, authenticated attacker to execute arbitrary Python code in the context of the recent running technique person.

Plex Software

“This issue permitted an attacker with accessibility to the server administrator’s Plex account to upload a malicious file by using the Digicam Add function and have the media server execute it,” Plex claimed in an advisory released at the time.

Explore the Hottest Malware Evasion Strategies and Prevention Techniques

All set to bust the 9 most harmful myths about file-dependent attacks? Be a part of our approaching webinar and grow to be a hero in the struggle against individual zero infections and zero-day security occasions!

RESERVE YOUR SEAT

The issue, which was found and noted to Plex by Tenable in March 2020, was resolved by Plex in edition 1.19.3.2764 launched on May 7, 2020. The existing edition of Plex is 1.31.1.6733.

“Unfortunately, the LastPass personnel never ever upgraded their application to activate the patch,” Plex claimed in a assertion. “For reference, the edition that resolved this exploit was about 75 variations in the past.”

Found this posting exciting? Adhere to us on Twitter  and LinkedIn to browse a lot more exceptional articles we post.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Almost Half of Industrial Sector Computers Affected By Malware in 2022
Next Post: Shein’s Android App Caught Transmitting Clipboard Data to Remote Servers shein's android app caught transmitting clipboard data to remote servers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
  • Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts

Copyright © TheCyberSecurity.News, All Rights Reserved.