As cited
Copy frozen at (site build).
threat intel
LastPass, Bitwarden users targeted with fake security alerts
LastPass has issued a warning about a phishing campaign that tricks users with fake security notices and directs them to fraudulent websites. The campaign exploits users' trust in the password manager to capture credentials or sensitive information. This reflects an ongoing trend of attackers impersonating legitimate security vendors to harvest user data.
Why it matters: LastPass and Bitwarden users are at immediate risk of credential theft; practitioners should alert users to verify security notices directly through official channels and never click links in unsolicited messages.
- Source published
- First seen by Cybersecurity Tracker