Was prepared to change all my darn credentials when clicking on that. For those clicking the comments first, the byline is: "LastPass has released a fix last week. Vulnerability details are now public. Users advised to update."
Just one example (this one from 2017) of many: https://bugs.chromium.org/p/project-zero/issues/detail?id=12.... Fundamental architectural flaws.
For more HN references, see https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
Asked about the experience he had reporting a 1Password vulnerability, he says:
"Astonishingly bad"
(source: https://twitter.com/taviso/status/1167311357957435392)