“Furthermore, #LastPass added that it will also start checking new or updated master passwords against a database of credentials previously leaked on the dark web to ensure that they don't match already compromised accounts.”
Wow, I really hope that they don’t choose the most straightforward approach to implement this feature. Given their security track record they actually might however, and it will be a disaster.
Unless they implement it as some kind of client-side check, this will weaken master password security massively. Such lookups require unsalted hashes, and sending out your master password like that to any remote party is bad. As in: really bad.