Back Feeds.4Sysops Phishing campaigns target LastPass and Bitwarden users with fake security alerts
A sophisticated phishing campaign is currently targeting users of LastPass and Bitwarden by sending fraudulent security notifications. These emails use spoofed domains like lastpassnewsletter.com to trick recipients into believing their account security policies have changed. The messages often include urgent calls to action, such as reviewing updated terms or responding to alleged unauthorized access attempts. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
