Brutal.

Home computer compromised by Plex(!!) which drops in a keylogger. LastPass DevOps employee then signs into their corp AWS console from home. pwned.

If someone is running Plex, they're almost definitely torrenting all sorts of shady stuff onto that same machine.

tldr: A whole security company compromised because one employee wouldn't pay for Netflix.

https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/

Reply to this note

Please Login to reply.

Discussion

👀 I have Plex, shutting it down

Oooooofffffff.

#[0]

👁️👄👁️

This just broke the oooofff meter 🤯

AWS log with no certificate.... WTF?????

Smells fishy 🐟

Imagine not using kodi instead of Plex

I have Plex in my phone and my Android TV. Should I remove it?

👀

I’ve been waiting for this story to drop.

The value of getting into a massive amalgamation of passwords will warrant all kinds of crazy attacks. General purpose computers are hopeless.

I believe you have the story slightly incorrect. A hacker exploited a vulnerability in an old version of Plex that had not been updated despite multiple prompts. Plex didn’t install a key logger.

#[4]