Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Crypto Market Rebound Wipes Out Nearly $500 Million in Short Positions

    Ethereum Climbs Above $2000: Investors Step In With Fresh Accumulation

    Mutuum Finance (MUTM) Prepares New Feature Expansion for V1 Protocol

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      How Smarsh built an AI front door for regulated industries — and drove 59% self-service adoption

      February 24, 2026

      Where MENA CIOs draw the line on AI sovereignty

      February 24, 2026

      Ex-President’s shift away from Xbox consoles to cloud gaming reportedly caused friction

      February 24, 2026

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026
    • Crypto

      Crypto Market Rebound Wipes Out Nearly $500 Million in Short Positions

      February 26, 2026

      Ethereum Climbs Above $2000: Investors Step In With Fresh Accumulation

      February 26, 2026

      Mutuum Finance (MUTM) Prepares New Feature Expansion for V1 Protocol

      February 26, 2026

      Bitcoin Rebounds Toward $70,000, But Is It a Momentary Relief or Slow Bull Run Signal?

      February 26, 2026

      IMF: US Inflation Won’t Hit Fed Target Until 2027, Delaying Rate Cuts

      February 26, 2026
    • Technology

      Samsung Galaxy S26 pre-order deals in Australia — here’s how you can save hundreds on the new devices

      February 26, 2026

      This Nuclear-Powered Battery Could Last 50 Years Without A Single Recharge

      February 26, 2026

      The Galaxy S26 lineup makes one thing clear: Samsung wants you in the Ultra

      February 26, 2026

      3 must-see horror movies on HBO Max if you want a serious midweek scare

      February 26, 2026

      Salesforce CEO Marc Benioff: This isn’t our first SaaSpocalypse

      February 26, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Fake LastPass, Bitwarden breach alerts lead to PC hijacks
    Technology

    Fake LastPass, Bitwarden breach alerts lead to PC hijacks

    TechAiVerseBy TechAiVerseOctober 16, 2025No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Fake LastPass, Bitwarden breach alerts lead to PC hijacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Fake LastPass, Bitwarden breach alerts lead to PC hijacks

    An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager.

    The messages direct recipients to download a binary that BleepingComputer has discovered installs Syncro, a remote monitoring and management (RMM) tool used by managed service providers (MSP) to streamline IT operations.

    The threat actors are using the Syncro MSP program to deploy the ScreenConnect remote support and access software.

    ‘Vulnerable’ old .EXE installs

    In a threat alert this week, LastPass makes it clear that the company did not suffer any cybersecurity incident and that the messages are a social engineering effort by a threat actor.

    “To be clear, LastPass has NOT been hacked, and this is an attempt on the part of a malicious actor to draw attention and generate urgency in the mind of the recipient, a common tactic for social engineering and phishing emails,” LastPass says.

    According to the company, the campaign started over the weekend, presumably to take advantage of the reduced staffing over the Columbus Day holiday weekend and delay detection.

    The phishing emails are well crafted and urge recipients to install a more secure desktop app that LastPass developed as an MSI replacement for the “outdated .exe format” that had weakenesses that allowed access to vault information.

    “Attackers exploited weaknesses in older .exe installations, which could, under certain conditions, allow unauthorized access to cached vault data,” reads the fake security alert from the threat actor.

    Phishing email impersonating LastPass
    Source: BleepingComputer

    LastPass notes that the fake messages come from ‘hello@lastpasspulse[.]blog’ but BleepingComputer also saw emails delivered from ‘hello@lastpasjournal[.]blog’.

    Bitwarden users also targeted

    The phishing emails also impersonate Bitwarden and share the same writing style and lure in an attempt to create a sense of urgency and convince recipients to follow the download link to an improved deskop application.

    Yesterday, BleepingComputer received a notice from ‘hello@bitwardenbroadcast.blog’ describing a similar security incident that prompted the release of a secure client app that users need to install.

    Phishing email impersonating Bitwarden
    Source: BleepingComputer

    At the time of writing, Cloudflare is blocking access to the landing pages included in the fraudulent emails and is marking them as phishing attempts.

    Legitmate tools for remote access

    BleepingComputer retrieved the binary samples distributed in the phishing emails targeting LastPass and Bitwarden users and found that they are functionally the same.

    The malware installs the Syncro MSP platform agent with parameters that hide its system tray icon in an effort to keep the user unaware of the new tool.

    Based on our observations, Syncro’s single purpose appears to be to deploy the ScreenConnect support tool as a “bring-your-own” installer, which gives the threat actor remote access to the endpoint.

    The Syncro agent is configured with very few options, suggesting that the threat actor limited to just the functionality they needed.

    The configuration files shows that the agent checks in with the server every 90 seconds. It does not have enabled the built-in remote access and doesn’t deploy the  remote support utilities Splashtop, which is bundled with the Syncro platform, or TeamViewer, for which an integration exists.

    Furthermore, the extracted configuration did not contain policies to deploy security solutions on the compromised endpoint, and disabled the Emsisoft, Webroot, and Bitdefender agents.

    Once ScreenConnect is installed on a device, the threat actors can remotely connect to a target’s computer and deploy further malware payloads, steal data, and potentially access the password vaults of users through saved credentials.

    Phishing for 1Password accounts

    Last week, another campaign targeted 1Password users with emails falsely warning that their accounts had been compromised. The indicators for that activity, from the wording in the message and landing URL, to the sender address (watchtower@eightninety[.]com) were different.

    The 1Password-themed phish
    Source: Malwarebytes

    Researchers at cybersecurity company Malwarebytes say that users clicking on an embedded button were taken to a phishing page (onepass-word[.]com) via a Mandrillapp redirection.

    The attacks targeting 1Password were first reported by Brett Christensen (Hoax-Slayer) on September 25.

    The landing page asking for the master password
    Source: Malwarebytes

    Users of password management tools should ignore such alerts and always login to the provider’s official website to check for any security alerts pending review.

    Important security incidents like those claimed in the emails are also broadly communicated across the companies’ blogs and via press releases, so double-checking on official channels is always a good practice.

    It is also worth remembering that companies won’t ever ask for the master password to your vaults.


    The Security Validation Event of the Year: The Picus BAS Summit

    Join the Breach and Attack Simulation Summit and experience the future of security validation. Hear from top experts and see how AI-powered BAS is transforming breach and attack simulation.

    Don’t miss the event that will shape the future of your security strategy

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleF5 releases BIG-IP patches for stolen security vulnerabilities
    Next Article PowerSchool hacker gets sentenced to four years in prison
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Samsung Galaxy S26 pre-order deals in Australia — here’s how you can save hundreds on the new devices

    February 26, 2026

    This Nuclear-Powered Battery Could Last 50 Years Without A Single Recharge

    February 26, 2026

    The Galaxy S26 lineup makes one thing clear: Samsung wants you in the Ultra

    February 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025693 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025279 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025160 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025122 Views
    Don't Miss
    Cryptocurrency February 26, 2026

    Crypto Market Rebound Wipes Out Nearly $500 Million in Short Positions

    Crypto Market Rebound Wipes Out Nearly $500 Million in Short Positions Prefer us on GoogleCrypto…

    Ethereum Climbs Above $2000: Investors Step In With Fresh Accumulation

    Mutuum Finance (MUTM) Prepares New Feature Expansion for V1 Protocol

    Bitcoin Rebounds Toward $70,000, But Is It a Momentary Relief or Slow Bull Run Signal?

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Crypto Market Rebound Wipes Out Nearly $500 Million in Short Positions

    February 26, 20262 Views

    Ethereum Climbs Above $2000: Investors Step In With Fresh Accumulation

    February 26, 20262 Views

    Mutuum Finance (MUTM) Prepares New Feature Expansion for V1 Protocol

    February 26, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.