Security researcher found a flaw in LastPass browser extension that could steal passwords. LastPass has fixed the issue in less than a day and awarded the researcher a $1,000 bug bounty. The same technique could have been used to steal passwords associated with other websites. Users should disable the autofill function and enable multi-factor authentication for better security. Well-known vulnerability researcher Tavis Ormandy has also tweeted overnight that he has also discovered a flaw. The flaw was discovered by a security researcher at Detectify Labs.”]
Source: https://grahamcluley.com/security-hole-fixed-lastpass/

