LastPass 2022: The Dev-Environment Breach That Came Back
August’s ‘contained’ developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.
August’s ‘contained’ developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.
A forums database with bcrypt hashes and salts hit a criminal forum. The real blast radius was everywhere else users reused passwords.
Slope’s telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
Fake Okta pages, real-time MFA relay, and one crew harvesting 10,000 identities. Why Cloudflare walked away clean and Twilio didn’t.
A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.
Rotating MAC addresses were supposed to make Bluetooth anonymous. May 2022’s synthesis of research, stalker hardware, and detection tools proved they never did.
GitHub’s OAuth tokens lived in Heroku’s infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.
Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.
37GB claimed, one account compromised, no customer data lost — and a DEV-0536 profile that taught the industry how social engineering beats MFA.
One contractor’s stolen credentials reached super-admin support tooling across 366 Okta tenants. The identity supply chain’s hardest lesson.
Seventeen users, one fake migration flow, and $1.7M in Apes gone — the phishing heist that made signature UX a security discipline.
No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.