LastPass said it fixed two vulnerabilities that were found last year. The disclosure comes ahead of a security conference where a paper describing the problems is due to be presented. One flaw could be exploited if a bookmarklet was used on a website rigged to attack it, LastPass wrote. The other flaw could allow an attacker to create a bogus one-time password (OTP) The paper has been accepted by the Usenix Security Symposium, which starts in San Diego on Aug. 20.”]