Hacker News new | ask | show | jobs
by username190 935 days ago
Bear in mind that not updating your Plex server could leave you open to security vulnerabilities. The most notable example of this is last year's massive LastPass breach, which began with malware installed on a LastPass employee's home computer via a RCE exploit in their out-of-date Plex Media Server instance. [1]

[1] https://www.pcmag.com/news/lastpass-employee-couldve-prevent...

2 comments

Why is "LastPass" almost always followed up with "Breach"? Are they exceptionally insecure, or just exceptionally transparent?
They are the most transparent company I have ever seen. And they have a big target on their backs...
Meh, this guy was targeted and opened an attachment or was tricked into doing something, that's how the malware originally got on his home computer, which then targeted the Plex server. You don't just randomly exploit someone's Plex server when it's behind their firewall.