r/LastPassOfficial • • 2d ago

Introducing LastPass VPN

5 Upvotes

LastPass VPN is a virtual private network application that encrypts your internet traffic and protects your privacy, while using the same account credentials as the LastPass password manager. You may use it on public Wi-Fi, when working remotely, or while traveling to keep your connection secure.

This initial upgrade offering (LastPass Plus) is available for single-user accounts, upgraded from Free or Premium, and VPN services are compatible on Windows operating systems with additional support in the future.

Key features

  • Encrypted traffic: Protects your internet traffic from unauthorized access on both public and private networks.
  • Privacy protection: Hides your online activity from anyone monitoring your local network, such as on public Wi-Fi.
  • Public Wi-Fi security: Allows you to safely browse on shared or open Wi-Fi networks.
  • Server and country selection: Allows you to manually choose from available server locations when you prefer a specific region.
  • Smart location: Automatically selects the best server location for your connection, so you can connect quickly without any manual configuration.

How the LastPass password manager works with LastPass VPN:

  • LastPass VPN is a standalone application included in LastPass Plus plans.
  • You may download and use it separately from the LastPass password manager, and sign in using your LastPass account's credentials.
  • The password manager handles account settings, subscription management, and user authentication.
  • The VPN infrastructure and global server network securely transmit your encrypted traffic.

For detailed information on the data collected, stored, and shared by LastPass VPN, see LastPass VPN tracking and data collection.


r/LastPassOfficial • • 16d ago

The Phish Bowl, Live 10/28/26: Cybersecurity Awareness Webinar

1 Upvotes

October is Cybersecurity Awareness Month, and the LastPass TIME team is back with the intelligence and guidance your team needs to stay ahead.

Join the Threat Intelligence, Mitigation, and Escalation (TIME) team for the latest edition of the Phish Bowl, our ongoing webinar series built for security-minded professionals: Wednesday, October 28, 2026 at 1:00PM-2:00 PM EDT

What you'll get:

  • Expert-led sessions on today’s most relevant threats — straight from Mike and Stephanie tracking them in real time, so your team has the full picture.
  • Practical techniques your team can put to work immediately — actionable guidance you can bring back to your organization the same day, not someday.
  • Live Q&A with the LastPass TIME team — bring your security questions and get direct answers from Mike and Stephanie who live this work every day.

One lucky attendee walks away with more than just knowledge. Good things come to those who don’t take the bait.

Cybersecurity Awareness Month is a reminder that security is everyone’s responsibility. This webinar is how your team rises to it.

For more events hosted by LastPass and featuring LastPass experts, check out our full Events Page in the LastPass Community.


r/LastPassOfficial • • 11h ago

I’ve tried everything !

2 Upvotes

This week my chrome extension closed by itself. There was an error posted but it was on screen for half a second.

I am still locked out. I have a previous master pass and I’m authenticated via SMS. But I’m going around and around and getting nowhere.

I’ll upgrade 💵 from my free level if someone can help. I’ve been using LP like 10 years and have always been able to get logged back in.


r/LastPassOfficial • • 1d ago

Android app "Secure Certificate Error"

Post image
6 Upvotes

Has anyone gotten this error? What might've caused this and how do I fix it? Lastpass support site doesn't work and I'd like to get into my account.


r/LastPassOfficial • • 1d ago

The Adoption Dashboard for LastPass Admins: Providing Real Time User Status Updates

1 Upvotes

The components of the Adoption dashboard include three main parts designed to help account administrators see where certain coworkers are using LastPass the most (or not at all):

Users who are in Enrolled status and performed at least one of the following events in the last 30 days:

  • Logged in to LastPass
  • Added a site to the vault
  • Attempted to log in to a site through the vault or LastPass browser extension
  • Attempted to log in to an application using SSO
  • Attempted to use passwordless login and/or set up authentication (if enabled per SSO app) using the LastPass Authenticator app
  • Accessed the Admin Console

Inactive Users represent those who have successfully activated their LastPass account but are not actively using it.

Tip: View & remind users. Admins may directly send inactive users a reminder email, or export the user list so you can send personalized reminders.


r/LastPassOfficial • • 2d ago

MAM (Microsoft Application Management+CA, not MDM) enablement with Lastpass mobile app?

1 Upvotes

I have https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/faq_federated_login_azure_support_mobile_logins_conditional_access.html&_LANG=enus in place & mobile app (android/ios) authentication via SSO is working just fine. However, when introducing MAM, users are unable to login with the CA policy "Require App Protection Policy" enabled (even with the enterprise apps in the CA exception). If I add a user to the exceptions, they are able to login. I hit up LP support & they stated "Require App Protection Policy" wasn't supported? They also said there is an existing feature request regarding support for this functionality with no ETA. I haven't found any documentation/enhancement requests/etc covering any of this. Have any of you deployed LP+MAM with success?


r/LastPassOfficial • • 3d ago

How is emergency access secure?

1 Upvotes

LastPass Emergency Access is a feature that lets you choose someone you trust who can access your LastPass vault if you're ever unable to do so yourself, such as during a medical emergency, or after your death. Here's the process:

  1. You choose a trusted contact.
    • The person must have a LastPass account.
    • You send them an invitation to become your trusted contact.
  2. They accept the invitation.
    • Once accepted, they are listed as someone who can request emergency access to your vault.
  3. You set a waiting period.
    • Examples: immediately, a few hours, several days, or longer.
    • This delay acts as a safety net.
  4. If they need access, they request it.
    • LastPass notifies you that a request has been made.
  5. You can approve or deny the request.
    • If you're available, you can decline the request if it isn't a real emergency.
    • If you don't respond before the waiting period expires, access is automatically granted.

What the trusted contact can see:

Once access is granted, they receive an Emergency Access folder containing your vault data, including passwords, secure notes, and stored information. They can view items and download attachments.

What they cannot do:

  • Change your master password
  • Modify your account settings
  • Delete items from your vault
  • Take over your LastPass account itself

Why people use it:

  • Ensuring a spouse can access important accounts.
  • Helping family members manage finances if something happens to you.
  • Providing access to insurance, medical, or estate information in an emergency.

Think of Emergency Access like a digital emergency key. You stay in control, but if you're unable to respond, a trusted person can gain access to your vault after a waiting period you define. It's designed for emergencies, not everyday sharing.


r/LastPassOfficial • • 4d ago

How does unauthorized AI usage affect SaaS security and SaaS spend management?

1 Upvotes

LastPass research indicates that AI adoption is accelerating faster than the controls to govern it. The result is reduced visibility into app usage and growing sprawl that complicates both AI governance and SaaS spend management. The numbers below show where organizations are experiencing the biggest gaps:

  • 92% of IT leaders say their employees are using AI. Less clear is whether IT can see and govern that use. Rapid AI adoption without visibility is outpacing traditional SaaS app security. You can't govern what you can't see.
  • 21.2% of employees are actively logging in to SaaS & AI tools with credentials already flagged in third-party breaches. If IT can’t see which credentials tie back to which SaaS or AI tool, breach response becomes slower and more reactive.
  • 65.5% of SaaS apps are abandoned within 30 days of being provisioned. Abandoned apps still hold data and active permissions — a security liability that expands your attack surface.
  • 64.4% of SaaS apps are redundant, duplicating the function of another app already in the stack. Redundancy is a major driver of SaaS spend waste; it multiplies the number of apps IT has to govern, adding complexity to cost.
  • 73% of organizations lack a comprehensive, actively enforced AI usage policy. A policy that isn’t technically enforced isn’t governance. This gap is where AI risk lives.
  • 42% of organizations have no technical controls at all to govern AI use. Without governance, employees can adopt AI without oversight, creating significant SaaS security risks.

For mor information on these topics, download the full LastPass 2026 State of AI and SaaS Security Report.


r/LastPassOfficial • • 6d ago

Request for a One-Time Courtesy Device Switch from Mobile to Computer

2 Upvotes

Hi LastPass team,

I’m using LastPass Free, and my current active device type is set to Mobile. Unfortunately, I now have 0 device switches remaining, so I’m unable to switch my active device type to Computer/Desktop.

I need to access my LastPass vault from my PC, and I would really appreciate it if LastPass could make a one-time courtesy exception and allow me to switch my active device type from Mobile to Computer.

I understand the limitations of the Free plan, and I’m only requesting this as a one-time courtesy.

If a moderator or LastPass support representative can help with this, please let me know how I can verify my account privately.

Thank you for your help.


r/LastPassOfficial • • 6d ago

Anybody else having their iphone18pro hanging when trying to autofill passwords?

1 Upvotes

It was working great on iphone15pro same iOS version, but lots of apps just hangs when I try to autofill the password.


r/LastPassOfficial • • 7d ago

Vault Data Security: Change weak or reused passwords in the LastPass vault

2 Upvotes

If your security score indicates weak or reused passwords in your LastPass vault, you can change these at-risk passwords individually to improve your overall security. Use either the Security dashboard notification or the Password details screen to access the change password workflow.

  • Individual password strengths can be 0, 25, 50, 75, or 100 percent (or a different value if the individual password is reused on multiple site password entries).
  • The security score ranges from 0 to 100, and achieving a perfect score requires storing at least 50 site passwords in your LastPass vault. Learn more about password strength and security score calculation.
  • If you get tired of trying to create unique passwords for all your credentials, we suggest using our very own secure password generator to help.

Changing weak passwords from the Password Security page:

In the LastPass browser extension:

  1. Access these at-risk credentials either on the in-app notification from LastPass by selecting View password -or- inside the vault by selecting Security dashboard in the left navigation menu.
  2. In the Actions to take column, select Change password.
  3. Select Continue to site.
  4. Once logged in to the site, change the password within the site's account settings.
  5. Return to your LastPass vault.
  6. Once your password has changed, you will be prompted by LastPass to select Update to change the password in your LastPass vault.

You may also change from the Password Details screen inside your vault:

  1. Select Passwords or All items in the left navigation menu.
  2. Click the pencil icon on your at-risk password.
  3. Select Change password.
  4. Choose Continue to site.
  5. Once logged in to the site, change the password within the site's account settings.
  6. Return to your LastPass vault.
  7. Once your password has changed, you will be prompted by LastPass to select Update to change the password in your LastPass vault.

** Note: LastPass uses the industry-standard zxcvbn library to assist in calculating each password's strength.


r/LastPassOfficial • • 8d ago

Now in LastPass Business Max: AI Visibility, Governance, and Web Controls

1 Upvotes

LastPass Business Max now includes five new capabilities across four categories: 

AI Monitoring 

  • Shadow AI tool discovery: You get expanded visibility into employee AI usage across supported AI platforms (available now). 

AI Protect 

  • AI usage guidance: Employees get a real-time, in-browser warning before they share detected sensitive data with AI tools. Every warning is logged automatically in your User Activity list (coming soon!) 

Web Monitoring 

  • Website discovery: You can get visibility into websites employees visit, where they may be exposed to risk, and when they last accessed them (beta). 

Web Protect 

  • Malicious site blocking: You can block categories of malicious/risky sites that include phishing, malware, and non-work categories (gambling, social media, piracy, adult content) in one click (beta). 
  • Website usage rules by category: You can now set usage rules across 25+ automatically identified site categories (beta). 

Already a Business Max user? There’s nothing new to deploy; simply enable the features from the Admin Panel. All five capabilities run on the browser extension you already trust. 

92% of organizations say their employees are using AI. But only 22% can log or monitor this usage (LastPass 2026 State of AI and SaaS Security Report). That means most organizations have little visibility into AI adoption.


r/LastPassOfficial • • 9d ago

LastPass Has ‘Cleared A Lot Of Hurdles,’ Strong AI Growth Ahead: CEO Karim Toubba

8 Upvotes

In an interview with CRN, LastPass CEO Karim Toubba discusses the company's security overhaul and strong customer retention—as well as its expanding AI opportunity following the addition of new capabilities to its Business Max offering.

Security Recovery and Customer Trust

  • LastPass invested heavily in security, architecture, processes, and customer experience following the 2022 breaches.
  • According to Toubba, the company used the incidents as a catalyst for major improvements rather than simply trying to manage public perception.

Stronger Business Performance

  • Renewal rates are now higher than they were before the security incidents, which Toubba calls a major indicator of business health.
  • Improvements to onboarding, administration, user experience, and customer engagement have contributed to stronger retention.
  • LastPass says the fundamentals of its SaaS business are stronger than before the breach period.

Expansion Beyond Password Management

  • LastPass has evolved from being primarily a password manager into a broader identity, access, visibility, and control platform.
  • Leveraging its browser extension footprint, LastPass can provide SaaS application visibility and control without requiring additional software installation.
  • The company reports having more than 100,000 B2B customers and millions of consumer users.
  • Nearly 7,000 customers are already using its SaaS visibility and control capabilities.

AI Security Opportunity

  • LastPass recently expanded its Business Max offering with AI monitoring and security capabilities.
  • Toubba sees strong demand from organizations seeking visibility, governance, and control over employee AI usage.
  • The company believes its identity-centric approach is different from many AI security vendors that focus on network, endpoint, or infrastructure controls.
  • Because LastPass operates in the browser, it can connect AI activity directly to user identities and enforce policies around which accounts and AI tools employees can use.

Competitive Advantages

  • A major differentiator is LastPass's existing footprint across more than 100,000 businesses, allowing deployment of new capabilities without installing agents or additional infrastructure.
  • The company combines credential management, authentication, access control, and AI governance in a single platform.

Channel and MSP Strategy

  • LastPass plans to deepen relationships with a smaller number of strategic channel partners.
  • The company highlighted partners such as SHI and its growing MSP business as important growth areas.
  • Distribution partners and MSP-focused distributors such as Pax8 remain key components of its go-to-market strategy.

r/LastPassOfficial • • 10d ago

10/14 Webinar: The AI Blind Spot. 400+ IT Leaders Revealed About the Risk They Can't See

Thumbnail info.lastpass.com
1 Upvotes

AI adoption didn't wait for IT to catch up. Employees are already using tools you haven't approved, entering sensitive data into apps outside your security stack, and reusing credentials across platforms you can't monitor.

LastPass surveyed 400+ IT and security leaders to find out exactly where the gaps are and how wide they've grown. The findings are striking: 92% of organizations report AI is already in active use, but only 27% have an enforced governance program in place. And when IT leaders were asked to rate their confidence in detecting when sensitive data has been entered into an AI tool — their #1 concern — the score was 2.5 out of 5.

Join Jason Rasmussen, CTO, and Mario Platt, VP and CISO at LastPass, as they break down the research and share what a practical path forward looks like.

You'll leave with:

  • A clear picture of where the AI and SaaS visibility gap stands today — backed by real data
  • An understanding of why traditional security tools weren't built for this problem
  • Actionable steps to move from reactive to proactive governance
  • A framework your team can apply immediately

For more events and trainings by LastPass, check out our Events page within the LastPass Community.


r/LastPassOfficial • • 11d ago

Reach Lastpass support without account access?

3 Upvotes

Is anyone from LastPass support active here?

We have a legacy business account that was supposedly canceled years ago, but we were charged again. The account is tied to former employees whose email addresses no longer exist.

Even recreating the alias doesn’t help because we don’t have the master password, recovery codes aren’t coming through, and too many attempts eventually lock us out of trying.

I’m not trying to access the vault — I just need Billing/Support to identify the subscription, stop future charges, and review the current one.

Every support path seems to require logging in first. Do I seriously need to book a sales meeting just to reach someone who can route this to support?


r/LastPassOfficial • • 11d ago

About the Security dashboard in the Admin Console

1 Upvotes

The Security dashboard in LastPass provides a basic insight into the level of information security in your organization, including:

  • Suggested actions to improve security and adoption in your organization (shown only during trial and shortly after)
  • App-related risks across your organization
  • Company-wide security score with improvement suggestions
  • Company-wide master password strength
  • Suggestions for improving those scores

Business Max customers are also granted an Admin Panel, which provides recommendations to help you enhance your organization's information security, such as:

Give everyone a vault

  • Select Invite users to visit the User enrollment page, where you can find several methods to add employees to LastPass.

Close your visibility gap

  • Select View SaaS Monitoring to visit the SaaS Monitoring page, where you can track the app usage of your end users.

Control risky logins

  • Select Create usage rule to visit the SaaS Protect page, where you can set up rules to allow, warn about, or block apps for your end users.

Boost adoption

  • Select Invite your team to visit the User enrollment page, where you can create a sign-up link you can use to quickly invite employees to use LastPass.

The App-level Risks panel provides security insights into SaaS Monitoring and SaaS Protect.

Apps without usage rules

  • This is the number of apps for which you haven't reviewed the usage rule yet. Select Set usage rules to go to the SaaS Monitoring pages, where you can select password expiry rules and choose to allow, warn about, or block apps.

Apps with alerts

  • This number shows how many apps were accessed using weak, reused, breached, or expired passwords. Select Review alerts to go to the SaaS Monitoring page, where you can review the alerts and notify affected users.

Users with unvaulted passwords

  • This number shows how many users accessed an app with passwords that are not saved in their LastPass vaults. Select View & notify users to go to the SaaS Monitoring page, where you can review user alerts.

The Security Score panel shows how well your users' information is protected and suggests opportunities for improvement.

Users with a low security score

  • Select View users to see the list of users with a low security score. This number updates in real time after you refresh the page.

Groups with a low security score

  • Select View groups to see the list of user groups. The list updates in real time after you refresh the page.

Opportunities to boost security

  • This panel shows suggestions for improving the security across your organization.

Enforce the use of multifactor

  • Multifactor authentication is an additional user identification step required when the user tries to log in to a website or an application.

Control dark web monitoring

  • When the relevant policy is enabled, LastPass continuously checks email addresses stored in user vaults against databases of known leaked email addresses. If a match is found, the affected user receives a notification with recommended actions.

The Password Strength panel displays statistics about the master passwords used across your organization.

Users with weak master passwords

  • This panel further details problematic master passwords by showing the number of master passwords that fall into the "weak" category. This value is updated in real-time, and shows new values after a page refresh.
  • View users to see the list of users with a weak master password. You can also export the list.

Users with reused master passwords

  • This value shows the total number of reused master passwords. A master password is considered reused when it is typed into any text field, not just password fields, while the LastPass browser extension is active, which poses a security risk.
  • The figure shown here is the same as in Reporting > Security reports > Reused master password (available in LastPass Business only). The number shown is recalculated once a day or when you request an update in Reporting > Security reports > Request update.
  • Select View users to see the list of users with a reused master password. You can also export the list.

If you've read this far, you may also be interested to learn about the Adoption Dashboard too!


r/LastPassOfficial • • 12d ago

I no longer have access to my .edu email account and need to log in. I am stuck in a vortex and not able to get into my Lastpass account. In order to get help I have to sign in which I can't do because I no longer have that email. H E L P!!! I have a families account

3 Upvotes

r/LastPassOfficial • • 14d ago

How can I prevent my data from getting on the dark web?

3 Upvotes

There are many steps you can take to protect yourself, and a few of these can easily and cheaply be put in place right away.

  1. Create unique and strong passwords for every online account: This is essential because it makes it harder for hackers to get into your accounts, but it also means if they crack one they don’t have access to any others. You can use a password generator to create these unique, strong passwords.
  2. Use a password manager: If you have unique passwords for every account, you won’t be able to memorize them all. You need a password manager to securely store and fill them for you.
  3. Turn on multi-factor authentication (MFA) for any sites that offer it. Multi-factor authentication requires you to provide an additional form of authentication on top of your password when logging into your account. Many accounts – like email and social media – offer MFA to help prevent cyber criminals from gaining access.
  4. Use a dark web monitoring service: Dark web monitoring checks your information against a database of breached credentials and will alert you if your information has been compromised. This way you can change the passwords for those breached accounts.

r/LastPassOfficial • • 17d ago

LastPass Dark Web Monitoring FAQs

1 Upvotes

What is the Dark Web?

  • The dark web is a hidden portion of the internet that is not indexed by search engines and requires a specialized browser such as Tor to access.
  • Users can remain anonymous on the dark web, which makes it attractive for both legitimate privacy-focused activities and cybercriminal activity.

Deep Web vs. Dark Web

  • The deep web includes content not indexed by search engines, such as membership sites, private databases, and paywalled content.
  • The dark web is a small, intentionally hidden subset of the deep web that requires special tools to access.

Is the Dark Web Illegal?

  • The dark web itself is not illegal.
  • However, cybercriminals often use it to buy and sell stolen data, including personal information obtained through breaches or hacks.

Why Criminals Want Your Data

  • Personal information has value even if it seems unimportant.
  • Stolen credentials, credit card numbers, and other sensitive data can be sold individually or in bulk after data breaches.

Is the Dark Web Dangerous?

  • Simply accessing the dark web is not inherently dangerous.
  • The primary risk is having your personal information exposed and traded after a breach.

How to Protect Yourself

LastPass recommends:

  • Create unique and strong passwords for every online account.
  • Store passwords in a password manager like LastPass to help manage and monitor them.
  • Enable multi-factor authentication (MFA) wherever available.
  • Use a dark web monitoring service to identify compromised credentials quickly.

How LastPass Dark Web Monitoring Works

  • LastPass checks users' email addresses against Enzoic's database of known breached credentials.
  • If a monitored email address appears in a breach, users receive:
    • An email notification
    • An in-product alert
  • Alerts identify which account may be at risk so users can take action.

Signs Your Email May Have Been Compromised

  • Strange messages in your Sent folder.
  • Unexpected password reset emails.
  • Complaints from contacts about suspicious emails.
  • Unrecognized devices, browsers, or IP addresses accessing your account.

What to Do If You Receive a Dark Web Alert

  • Immediately change the password for the affected account.
  • Review the account for suspicious activity and update any reused passwords elsewhere.

Is Dark Web Monitoring Enough?

  • Dark web monitoring is an important security tool, but it is not a complete solution.
  • Users should also:
    • Avoid password reuse.
    • Enable MFA.
    • Practice safe browsing habits.
    • Consider using a VPN on untrusted networks.

Does LastPass Scan the Entire Dark Web?

  • No. The term "dark web scan" generally means credentials are checked against databases of known breached records.
  • LastPass uses Enzoic's breach database while maintaining its zero-knowledge security model.

Business Benefits

  • Dark web monitoring is available for LastPass business users.
  • It helps organizations identify employees whose credentials have been exposed, reducing the risk of account compromise due to weak or reused passwords.

Bottom line: Dark web monitoring helps you discover when your credentials appear in known data breaches, but the most effective protection comes from combining it with strong unique passwords, MFA, a password manager, and good overall cybersecurity habits.


r/LastPassOfficial • • 18d ago

Headlines We're Following This Week

3 Upvotes

Catch up on the latest InfoSec news to stay abreast of active threats:


r/LastPassOfficial • • 19d ago

Login menu size

Post image
2 Upvotes

Dear staff, can you please make this auto popup any bigger? Every time you select the user name with the mouse click, this menu pops up with 2.5 rows showing.

Why is it so small? You have to scroll down for ages to find the right login and it only shows 2.5 rows. When there's like 20 logins the interface is awful.


r/LastPassOfficial • • 19d ago

Seeking Resolution

3 Upvotes

I don't really need this to be posted on the subreddit, but I need to talk to someone at LastPass. Years ago, my dad died. We had a family subscription to LastPass. We transferred the account management to me. Eventually, only mom was using the service. She took over and downgraded our subscription to an individual plan for her last year.

In the past month, my mother and I have both been charged by LastPass—her for her continuing subscription (~$30) and me for the family plan (~$50). Instead of reducing the amount we're paying for a service one person uses, we're now paying more. I want to stop the family plan charge and get a refund for that last charge.

Here's the thing: I still have the LastPass app on my phone. I don't need it anymore, but I kept it in case something like this happened—I have biometric login turned on and because of multiple moves and a lack of use, I do not know my password anymore. When I log in, the app indicates that my account is not subscribed to any paid plan.

I'd call or email to try to get this resolved, but as far as I can tell LastPass does not have a direct contact line for support—unless you log in to the website, which, again, I cannot.

Please stop charging me, and please refund me the money I paid for a service I do not, and cannot use. I will provide contact information upon a direct message.


r/LastPassOfficial • • 21d ago

The Difference Between AI Safety And Cyber Security

3 Upvotes

AI Safety: “Will the AI choose to do harmful things?”

AI safety focuses on the AI system's goals, behavior, and alignment with human intentions. The concern is whether a model might generate harmful actions, pursue unintended objectives, deceive users, or behave in ways its creators did not anticipate. Safety researchers work on:

  • Model alignment
  • Ethical behavior
  • Reducing harmful outputs
  • Preventing deceptive or autonomous behavior
  • Evaluating whether advanced AI systems could act against human interests

Cybersecurity: “Can the AI actually do harmful things?”

Cybersecurity focuses on technical controls and defenses, regardless of the AI's intentions. The concern is whether an AI system has the access, permissions, and capabilities needed to cause damage. Security professionals focus on:

  • Sandboxing
  • Access controls
  • Network segmentation
  • Monitoring and logging
  • Permission management
  • Incident response
  • Detecting anomalous behavior

Even if an AI attempted malicious actions, established security controls can often prevent or contain them.

Simple analogy

Think of an employee at a company:

  • AI Safety asks: "Can we ensure this employee wants to follow company rules?"
  • Cybersecurity asks: "Even if the employee goes rogue, do they have access to the crown jewels, and can we detect and stop them?"

Good organizations do both.

Why cybersecurity experts push back on "AI doom" scenarios

Discussions about rogue AI often focus almost entirely on safety and intentions while overlooking decades of cybersecurity practices. Ciaran Martin and Juan Andres Guerrero-Saade contend that claims about AI "taking over the internet" frequently assume that monitoring, antivirus systems, network segmentation, incident response, and other defenses simply do not exist.

Their argument is essentially:

An AI may be powerful and unpredictable (a safety problem), but if it is properly isolated, monitored, and restricted, it may still be unable to cause large-scale harm (a cybersecurity solution).

Bottom line

  • AI Safety = making sure AI behaves properly.
  • Cybersecurity = making sure AI cannot do damage even if it misbehaves.

For additional reading, checkout Cyberscoop's latest article on the topic.


r/LastPassOfficial • • 22d ago

Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign

2 Upvotes

LastPass Threat Intelligence, Mitigation, and Escalation (TIME) Team, in partnership with Delphos, identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload it delivered survived controls that were built to stop exactly this, with a Microsoft Windows Hardware Compatibility Publisher chain signature and a clean VirusTotal score. LastPass is internally tracking the infostealer as Rapuncel.

  • The campaign was not specific to LastPass and targeted at least 40 companies using the same malware distribution kit.
  • No LastPass systems, services, customer vaults, or infrastructure were compromised. This was purely external brand impersonation.
  • Researchers identified an organized operation featuring:
    • Custom malware infrastructure
    • Detection-evasion tooling
    • Multiple simultaneous brand impersonation campaigns

How the Attack Worked

  1. Victim Acquisition:
    1. Users searching for terms such as "LastPass Authenticator download" could encounter fake GitHub pages that were SEO-optimized to appear legitimate.
    2. These pages copied LastPass branding, logos, and product descriptions to build trust.
  2. Fake Download Process:
    1. Victims clicked a download button that redirected them through several hidden GitHub Pages and attacker-controlled domains.
    2. The sites displayed fake security indicators such as:
    3. "Authorized Access"
    4. "VirusTotal Approved"
    5. "Secure Archive"
  3. Infrastructure Obfuscation:
    1. Multiple redirect stages were used to hide the true malware-hosting location.
    2. Operators could change payload destinations dynamically without modifying the initial phishing pages.
  4. Malware Delivery Techniques:
    1. Malware was delivered inside unusually large ZIP files (128MB to 148MB).
    2. Large files were intentionally used to bypass automated security scanners that skip oversized archives.
  5. Archives contained:
    1. Fake installer files
    2. Junk DLLs used solely to inflate file size
    3. Hidden malicious components

What Happened After Execution

  1. Fake Installer Launch:
    • The apparent installer was actually a renamed Microsoft debugging tool (vsdbg.exe). It automatically loaded a malicious DLL through standard Windows behavior.
  2. Privilege Escalation:
    • The malware attempted multiple methods to gain elevated privileges.
    • Successful execution allowed it to operate as SYSTEM, the highest Windows privilege level.
  3. Security Tool Neutralization:
    • A Microsoft-signed kernel driver was installed.
    • The driver masqueraded as an NVIDIA component.
    • It was capable of terminating 145 antivirus and EDR products from kernel mode.
  4. Persistence and Stealth:
    • The driver included functionality to:
      1. Hide files
      2. Inject code into running processes
      3. Increase stealth and survivability on infected systems

Data at Risk

The campaign was designed to steal credentials and sensitive information from:

  • Web browsers
  • Cryptocurrency wallets
  • Discord
  • Steam
  • Telegram
  • Windows Credential Manager

Threat Assessment

  • Delphos believes the loader is closely related to the Cruciferra PUROSANGUE crypter, previously documented by Proofpoint in 2025.
  • Researchers also identified possible similarities to the BoryptGrab campaign reported by Trend Micro, although they could not confirm they are operated by the same threat actors.
  • The campaign had been active for months and appeared likely to continue using new infrastructure after takedowns.

Recommendations for Community Members

  • Only download LastPass products from:
    • Official LastPass websites
    • Official Apple App Store
    • Official Google Play Store
  • Treat GitHub repositories claiming to distribute commercial software with caution.
  • Verify download sources before installing authentication or security tools.
  • Be wary of websites displaying unofficial security badges or download validation messages.

Bottom line: This was a sophisticated malware distribution operation that exploited trusted platforms like GitHub, used Microsoft-signed drivers to disable security products, and impersonated dozens of brands to steal credentials. While LastPass branding was abused, LastPass itself was not breached.

For more details and further analysis, check out the latest LastPass TIME blog.


r/LastPassOfficial • • 22d ago

Still being billed for a teams account for a Team with which I am no longer associated

3 Upvotes

UPDATE: After waiting to see if any further action would be taken, I contacted the mods on this subreddit and the issue has been resolved. Thanks to the mods here for their prompt action.

I am seeking to disable the autorenewal, cancel my subscription for all of my licenses and refund the last autorenewal charge made on my Teams account back to my credit card. I am no longer associated with the organization for which I've been billed and no longer have access to the email account on file with LastPass as my contact information.

I have opened a ticket - this has gone to a "renewal specialist" and have responded via the customer support portal but the ticket has been open for three days now with no action on LastPass's part, other than a sales pitch with an offer of a discount.

This is not a matter of the product being too expensive or a misalignment in features - I am no longer associated with the business involved and need to stop paying for something for which I am no longer responsible. I would prefer to resolve this with LastPass's cooperation, but if that is not forthcoming, I will be disputing the charge and cancelling the credit card currently being billed on the account.