VulnerabilityBleeping Computer
8.0 — CRITICAL
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
LastPass suffered a data breach due to the Klue supply chain attack, where hackers accessed customer data after stealing OAuth tokens from the compromised third-party market intelligence platform.
⚙️Technical Details
Affected Systems
Salesforce environmentKlue (klue.com)
Attack Vectors
OAuth token theft via compromised integration service credentials
💥Impact Assessment
Severity: high
🛡️Recommended Actions
1Monitor email and phone communications for suspicious activity
2Verify sender domains before responding to unsolicited requests
3Rotate exposed API/OAuth tokens and disable employee access to Klue
📦Affected Products
LastPass products, services, and infrastructure
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
