Tag

Passwordsecurity

All articles tagged with #passwordsecurity

"LastPass Mandates 12-Character Minimum for Master Passwords Post-Security Update"
technology-and-cybersecurity2 years ago

"LastPass Mandates 12-Character Minimum for Master Passwords Post-Security Update"

LastPass is enforcing a new security measure requiring all users to have a master password of at least 12 characters. This change, effective from April 2023 for new accounts and password resets, now extends to all accounts to enhance security following two breaches in 2022. The company will also check new or updated master passwords against a database of credentials leaked on the dark web. Additionally, LastPass faced issues with a forced multi-factor authentication re-enrollment process in May 2023. These security updates come after LastPass experienced significant breaches in 2022, which led to the theft of source code and customer vault data, and were later linked to a cryptocurrency theft totaling $4.4 million. LastPass is widely used, with over 33 million individual users and 100,000 businesses.

"Persistent Malware Exploits Google OAuth to Hijack Accounts Despite Password Resets"
technology-cybersecurity2 years ago

"Persistent Malware Exploits Google OAuth to Hijack Accounts Despite Password Resets"

Cybercriminals are exploiting an undocumented Google OAuth endpoint called MultiLogin to hijack user sessions, allowing them to maintain access to Google services even after victims reset their passwords. The exploit has been adopted by various malware-as-a-service families, enabling them to persistently steal information. Google has acknowledged the issue and stated that users can invalidate stolen sessions by logging out of the affected browser or remotely via the user's devices page. Enhanced Safe Browsing and regular monitoring of account activity are recommended to users for additional security. The situation underscores the need for advanced security measures to combat sophisticated cyber threats.