Wednesday, March 22, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Mitigate the LastPass Attack Surface in Your Environment with this Free Tool

justmattg by justmattg
January 7, 2023
in Cyber Security
0
Mitigate the LastPass Attack Surface in Your Environment with this Free Tool
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

READ ALSO

New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War

Controlling Third-Party Data Risk Should Be a Top Cybersecurity Priority


Jan 05, 2023The Hacker NewsPassword Management / IT Breach

LastPass Attack Surface

The latest breach announced by LastPass is a major cause for concern to security stakeholders. As often occurs, we are at a security limbo – on the one hand, as LastPass has noted, users who followed LastPass best practices would be exposed to practically zero to extremely low risk. However, to say that password best practices are not followed is a wild understatement. The reality is that there are very few organizations in which these practices are truly enforced. This puts security teams in the worst position, where exposure to compromise is almost certain, but pinpointing the users who created this exposure is almost impossible.

To assist them throughout this challenging time, Browser Security solution LayerX has launched a free offering of its platform, enabling security teams to gain visibility into all browsers on which the LastPass extension is installed and mitigate the potential impacts of the LastPass breach on their environments by informing vulnerable users and require them to implement MFA on their accounts and if required, roll out a dedicated Master Password reset procedure to eliminate adversaries’ abilities to leverage a compromised Master Password for malicious access (To request access to the free tool, fill this form)

Recapping LastPass’s Announcement: What Data Do Adversaries Have and What’s the Risk?

Per LastPass’s website, ‘The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.’

The derived risk is that ‘the threat actor may attempt to use brute force to guess your master password and decrypt the copies of vault data they took. Because of the hashing and encryption methods we use to protect our customers, it would be extremely difficult to attempt to brute force guess master passwords for those customers who follow our password best practices.’

Not Implementing LastPass Password Best Practices Exposes the Master Password to the Vault

The last section about ‘best practices’ is the most alarming one. Password best practices? How many people maintain password best practices? The realistic – yet unfortunate – answer is: not many. That holds true even in the context of corporate-managed applications. When it comes to personal apps, it’s not an exaggeration to assume that password reuse is the norm rather than the outlier. The risk LastPass’s breach introduces apply to both use cases. Let’s understand why.

The Actual Risk: Malicious Access to Corporate Resources

Let’s divide organizations into two types:

Type A: Organizations where LastPass is used as part of the company policy for vaulting passwords to access corporate-managed apps, either for all users or in specific departments. In that case, the concern is straightforward – an adversary that manages to crack or obtain an employee’s LastPass Master Password could easily access the corporate’s sensitive resources.

Type B: Organizations where LastPass is used independently by employees (whether for personal or work use) or by specific groups in the organization, without IT knowledge, for apps of choice. In that case, the concern is that an adversary who manages to crack or obtain an employee’s LastPass Master Password would take advantage of users’ tendency for password reuse and, after compromising the passwords in the vault, will find one that is also used to access corporate apps.

The CISO’s Dead End: Certain Threat but Extremely Low Mitigation Capabilities

Regardless of whether an organization falls into type A or B, the risk is clear. What intensifies the challenge for the CISO in this situation is that while there is high probability – not to say certainty – that there are employees in her or his environment whose user accounts are likely to become compromised, the CISO has very limited ability to know who these employees are, let alone take the required steps to mitigate the risk they impose.

LayerX Free Offering: 100% Visibility into LastPass Attack Surface as Well as Proactive Protection Measures

LayerX has released a free tool that assists security teams in understanding their organization’s exposure to the LastPass breach, maps all the vulnerable users and applications, and applies security mitigations.

LayerX’s tool is delivered as an enterprise extension to the browser your employees are using and hence provides immediate visibility into all browser extensions and browsing activities of every user. This enables CISOs to gain the following:

  • LastPass Usage Mapping: End-to-end visibility into all browsers on which the LastPass extension is installed, regardless of whether it’s part of the corporate policy (type A) or personally used (type B). The tool maps all applications and web destinations whose credentials are stored in LastPass. It should be noted that the visibility challenges for type B organizations are much more severe than for type A and cannot be addressed by any solution except for LayerX’s tool.
LastPass Attack Surface
LayerX’s LastPass Report
LastPass Attack Surface
The LayerX notification sent to vulnerable users
  • Identifying Users at Risk: Leveraging this knowledge, security teams can inform vulnerable users and require them implement MFA on their accounts. They can also roll out a dedicated Master Password reset procedure to eliminate adversaries’ abilities to leverage a compromised Master Password for malicious access.

To get access to the free tool, fill this form.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Related Posts

New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War
Cyber Security

New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War

March 21, 2023
Controlling Third-Party Data Risk Should Be a Top Cybersecurity Priority
Cyber Security

Controlling Third-Party Data Risk Should Be a Top Cybersecurity Priority

March 21, 2023
55 Zero-Day Vulnerabilities Weaponized in 2022
Cyber Security

55 Zero-Day Vulnerabilities Weaponized in 2022

March 21, 2023
Crypto Drainers Are Ready to Ransack Investor Wallets
Cyber Security

Cybersecurity Threats Overhyped or Not?

March 21, 2023
New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads
Cyber Security

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

March 20, 2023
Shouldering the Increasingly Heavy Cloud Shared-Responsibility Model
Cyber Security

Shouldering the Increasingly Heavy Cloud Shared-Responsibility Model

March 20, 2023
Next Post
What Is a Stun Gun? | Self Defense 101 | The HomeSecurity Superstore

What Is a Stun Gun? | Self Defense 101 | The HomeSecurity Superstore

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices

February 9, 2023
Half of Apps Have High-Risk Vulnerabilities Due to Open Source

Half of Apps Have High-Risk Vulnerabilities Due to Open Source

February 22, 2023
Iranian Nation-State Group Sanctioned by U.S. Behind Charlie Hebdo Hack

Iranian Nation-State Group Sanctioned by U.S. Behind Charlie Hebdo Hack

February 7, 2023
WhatsApp Introduces Proxy Support to Help Users Bypass Internet Censorship

WhatsApp Introduces Proxy Support to Help Users Bypass Internet Censorship

January 7, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • Zighra Gets Canada’s OK, Worldcoin Launches ‘World ID’: Identity News Digest
  • New ‘Bad Magic’ Cyber Threat Disrupt Ukraine’s Key Sectors Amid War
  • Controlling Third-Party Data Risk Should Be a Top Cybersecurity Priority
  • Exploring transformers for behavioral biometrics
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.