Polymer

Download free DLP for AI whitepaper

Summary

  • LastPass suffered a data breach after a developer account was compromised. 
  • No customer data was stolen, but the threat actors got away with LastPass source code and some proprietary technical information.
  • This breach underscores the importance of identity and access management.

Over the weekend, the popular password management tool, LastPass, published a blog post, letting its customers know that it suffered a data breach. Here’s everything you need to know.

What’s LastPass?

LastPass is a very well known security tool used by individuals and organizations alike to streamline password management. 

Essentially, LastPass works by storing all your usernames and passwords for your online accounts (Outlook, Netflix, WordPress and so on) in a singular vault, accessible through a ‘master password’ that you set. 

When you go to the login page of these websites, LastPass automatically populates the login form for you, saving you from having to remember numerous different passwords. 

What is the LastPass data breach?

In a statement, LastPass explained that it noticed suspicious activity about two weeks ago and launched an immediate investigation.

The company discovered that threat actors had gained access to the LastPass development environment, where they stole LastPass source code and some proprietary technical information. 

According to LastPass’ CEO, Karim Toubba, there is “no evidence that this incident involved any access to customer data or encrypted password vaults.” He also shared that LastPass “products and services are operating normally.”

This is good news for LastPass customers. It means your data is safe and you don’t need to take any further action to secure your LastPass account.

How did the LastPass data breach happen?

Toubba shared that threat actors got into the development environment “through a single compromised developer account”. There aren’t any details available about how the account was hacked or how long it was compromised for. 

This type of attack, known as credentials compromise, is extremely common and highly successful for cyber-criminals. As Verizon’s Data Breach Investigations Report found, 50% of cyber-attacks rely on stolen credentials. In fact, this attack type is the number one cause of data breaches—and has been for the last four years. 

The LastPass data breach reinforces that, no matter how big your company is, no entity is immune from credentials compromise attacks. 

What lessons can we learn from the LastPass data breach? 

Incidents relating to compromised credentials underscore the importance of robust identity and access management (IAM) principles, such as: 

  • Implement the principle of least privilege: You’ll greatly reduce the likelihood of a successful credentials compromise attack by segregating your users. Ensure that employees only have the access rights they need to do their job—and nothing more. 
  • Enable multi-factor authentication (MFA): Multi-factor authentication requires your users to verify their identities in at least two ways, such as through a password and a mobile authentication code. MFA is a straightforward way to bolster security.
  • Audit users regularly: Dormant and inactive accounts are a dream for hackers, enabling them to break into your systems without being noticed. To ensure this doesn’t happen, you need to regularly audit your user base, shutting down inactive accounts as soon as an employee changes roles. 
  • Remember data loss prevention (DLP): IAM plays an important role in securing your enterprise, but it’s not foolproof. With so many different employee accounts and so much data scattered all over the place, you need to complement IAM with a solution that protects data from the moment it is created, no matter where it travels. That’s where DLP comes in. 

How DLP combats credentials compromise

Polymer DLP autonomously discovers and protects sensitive data across your cloud applications. Using cloud-native controls, it enforces granular access controls and monitors user activity for signs of credentials compromise.

If the solution identifies suspicious activity, it will block the user in question from accessing sensitive company data, and alert the IT team for further investigation, so your data stays safe – even if a user account is hacked. 

Polymer is a human-centric data loss prevention (DLP) platform that holistically reduces the risk of data exposure in your SaaS apps and AI tools. In addition to automatically detecting and remediating violations, Polymer coaches your employees to become better data stewards. Try Polymer for free.

SHARE

Get Polymer blog posts delivered to your inbox.

RATU311

thor311 tajen bali

thor311 alternatif

situs toto4d

thor311 toto4d

thor311 akses

ceri188

KUPU178

daftar ceri188

cery188

ceri188

KUPU178

KUPU178

slot gacor

kupu 178

kupu178

ceri1888

ceri188

slot online

hoki311

togel online

ceri188

ding dong

ratu311

slot gacor

kupu178

live casino

kupu178

RATU311

mix parlay

ceri188

judi bola online

thor311 slot

RATU311

HOKI311

HOKI311

THOR311

RATU311

RATU311

KUPU178

THOR311

THOR311

ceri188

ratu311

slot online

hoki311

kupu178

togel online

kupu178

slot gacor

ceri188

judi bola online

ceri188

ratu311

kupu178

RATU311

RATU311

live casino roullete

ceri188

slot pg soft

kupu178

KUPU178

KUPU178

THOR311

THOR311

THOR311

THOR311

RATU311

KUPU178

KUPU178

THOR311

THOR311

THOR311

RATU311

thor311 domino qq

thor311 akses

thor dingdong

THOR311

ceri188

ceri188

KUPU178

RATU311

RATU311

kupu178

kupu178

HOKI311

togel

kupu178

mix parlay

ceri188

slot online

kupu178

THOR311

THOR311

KUPU178

KUPU178

kupu178

hoki311

togel online

kupu178

ceri188

ceri188

www.vrcorporate.in

phbalance.vn

togel hongkong

kupu178

slot gacor

kupu178

kupu178

ceri188

kupu178

RATU311

KUPU178

RATU311

RATU311

slot online

kupu178

THOR311

KUPU178

slot mahjong ways

hoki311

slot gacor

ceri188

kupu178

Casino Baccarat Online

kupu178

kupu178

ceri188

toto macau

KUPU178

Slot Gacor

KUPU178

RATU311

Mahjong ways

KUPU178

THOR311

RATU311

RATU311

RATU311

KUPU178

KUPU178

RATU311

RATU311

RATU311

Toto Togel

KUPU178

CERI188

Slot Sweet Bonanza 2500

KUPU178

RATU311

RATU311

KUPU178 X SLOT777

judi bola online

THOR311

KUPU178 SLOT TERPERCAYA

KUPU178 TOGEL

TOTO 4D MACAU

KUPU178

KUPU178

THOR311

HOKI311

KUPU178

RATU311

Slot Mahjong Ways

KUPU178

CERI188

Slot Online Resmi

KUPU178

RATU311 SLOT ONLINE

KUPU178

KUPU178: Link Akses Resmi

KUPU178: Strategi Menang Di Game Live Casino

KUPU178

KUPU178: Minimal 200 Rupiah

THOR311

THOR311

THOR311

THOR311

THOR311

KUPU178

Slot Thailand

CERI188

CERI188

THOR311 RTP

RATU311

RATU311

CERI188

KUPU178 TOTO SLOT

CERI188 TOTO Singapore

THOR311

CERI188

RATU311: Alternatif karnpuracollege

Thor311 Terbaru

THOR311 MAHJONG

RATU311: BONUS SABUNG AYAM

CERI188: Masuk Akun Slot Super Cepat

CERI188

CERI188

THOR311

HOKI311

HOKI311

RATU311

HOKI311

KUPU178

RATU311

RATU311

RATU311

THOR311

CERI188

CERI188

RATU311

RATU311

RATU311

Game Thor311

HOKI311

HOKI311

RATU311

HOKI311

HOKI311

THOR311

RATU311 NONTON BOLA

HOKI311 Link QRIS EWALLET

RATU311

HOKI311 Link Apk Resmi

CERI188

RATU311 judi bola

KUPU178

HOKI311

RATU311

THOR311

HOKI311

KUPU178

KUPU178

KUPU178

RATU311

RATU311

KUPU178

THOR311

KUPU178

RATU311

THOR311